⤷ Title: The Modern Penetration Tester’s Journey: More Than Just Breaking Things
════════════════════════
𐀪 Author: Yen Wang
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 23:22:39 GMT
════════════════════════
⌗ Tags: #penetration_testing #hackthebox #pentesting #penetration_tester #cpt
════════════════════════
𐀪 Author: Yen Wang
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 23:22:39 GMT
════════════════════════
⌗ Tags: #penetration_testing #hackthebox #pentesting #penetration_tester #cpt
Medium
The Modern Penetration Tester’s Journey: More Than Just Breaking Things
A comprehensive look at what it really takes to succeed in penetration testing
⤷ Title: The 2026 Surge: Apple’s 15-Product Roadmap Includes Foldable iPhone & AI Smart Home
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:57:22 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Apple Intelligence #Foldable iPhone #iPhone 18 #M6 Chip #MacBook Pro #Roadmap #Siri #Smart Home
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:57:22 +0000
════════════════════════
⌗ Tags: #Technology #Apple #Apple Intelligence #Foldable iPhone #iPhone 18 #M6 Chip #MacBook Pro #Roadmap #Siri #Smart Home
Daily CyberSecurity
The 2026 Surge: Apple's 15-Product Roadmap Includes Foldable iPhone & AI Smart Home
Apple’s ambitious 2026 roadmap features 15+ major products: iPhone 18, a foldable iPhone, M6 MacBooks with touchscreens, and a massive Apple Intelligence rollout.
⤷ Title: Operation SkyCloak Targets Russian/Belarusian Military With LNK Exploit and OpenSSH Over Tor Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:41:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russian Espionage #SkyCloak #Tor network
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:41:01 +0000
════════════════════════
⌗ Tags: #Cyber Security #Belarus Military #DLL Sideloading #LNK Exploit #obfs4 #OpenSSH #Russian Espionage #SkyCloak #Tor network
Daily CyberSecurity
Operation SkyCloak Targets Russian/Belarusian Military With LNK Exploit and OpenSSH Over Tor Backdoor
SEQRITE exposed SkyCloak, an espionage campaign targeting Russian/Belarusian military personnel. It uses malicious LNK files to deploy OpenSSH over Tor obfs4 bridges for stealthy, persistent remote access.
⤷ Title: Cloud Abuse: TruffleNet BEC Campaign Hijacks AWS SES and Portainer to Orchestrate 800+ Malicious Hosts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:37:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AWS SES #BEC #Cloud Abuse #Portainer #Stolen Credentials #Supply Chain #TruffleNet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:37:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AWS SES #BEC #Cloud Abuse #Portainer #Stolen Credentials #Supply Chain #TruffleNet
Daily CyberSecurity
Cloud Abuse: TruffleNet BEC Campaign Hijacks AWS SES and Portainer to Orchestrate 800+ Malicious Hosts
Fortinet exposed TruffleNet, a massive BEC campaign using stolen AWS keys to exploit Amazon SES for email fraud. It abuses Portainer as a C2 and uses TruffleHog for reconnaissance.
⤷ Title: Tap-and-Steal: Over 760 Android Apps Exploit NFC/HCE for Payment Card Theft in Global Financial Scam
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:32:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android NFC #Brazil #financial fraud #Host Card Emulation #Payment Card Theft #russia #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:32:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android NFC #Brazil #financial fraud #Host Card Emulation #Payment Card Theft #russia #Telegram C2
Daily CyberSecurity
Tap-and-Steal: Over 760 Android Apps Exploit NFC/HCE for Payment Card Theft in Global Financial Scam
Zimperium found 760+ Android apps exploiting NFC/HCE to steal payment data. The malware impersonates 20 banks across Russia, Poland, and Brazil, using Telegram for criminal coordination.
⤷ Title: Chinese APT UNC6384 Pivots to Europe, Exploits Windows LNK Flaw to Deploy PlugX via Canon DLL Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:29:48 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #Chinese APT #DLL Sideloading #Espionage #European Diplomacy #LNK Exploit #PlugX #UNC6384 #ZDI_CAN_25373
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:29:48 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #Chinese APT #DLL Sideloading #Espionage #European Diplomacy #LNK Exploit #PlugX #UNC6384 #ZDI_CAN_25373
Daily CyberSecurity
Chinese APT UNC6384 Pivots to Europe, Exploits Windows LNK Flaw to Deploy PlugX via Canon DLL Sideloading
Researchers at Arctic Wolf Labs have uncovered an extensive cyber espionage campaign by UNC6384, a Chinese-affiliated threat actor, targeting European diplomatic entities across Hungary, Belgium, …
⤷ Title: Android AI Scam Defense Blocks 10 Billion Monthly Threats; Users 58% More Likely to Avoid Scam Texts Than iOS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:26:48 +0000
════════════════════════
⌗ Tags: #Android #Cybercriminals #AI Scam Protection #Android security #Call Protection #Google Messages #iOS Comparison #Mobile Fraud #YouGov
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:26:48 +0000
════════════════════════
⌗ Tags: #Android #Cybercriminals #AI Scam Protection #Android security #Call Protection #Google Messages #iOS Comparison #Mobile Fraud #YouGov
Daily CyberSecurity
Android AI Scam Defense Blocks 10 Billion Monthly Threats; Users 58% More Likely to Avoid Scam Texts Than iOS
In a recent blog post, Google revealed that “in the last 12 months, fraudsters have used advanced AI tools to create more convincing schemes, resulting in over $400 billion in stolen funds globall…
⤷ Title: North Korean APTs Upgrade Arsenal: Kimsuky Uses Stealthy HttpTroy, Lazarus Deploys New BLINDINGCAN RAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:22:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BLINDINGCAN #Cyberespionage #DLL Sideloading #HttpTroy #Kimsuky #Lazarus Group #North Korea APT #Stealth Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:22:58 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BLINDINGCAN #Cyberespionage #DLL Sideloading #HttpTroy #Kimsuky #Lazarus Group #North Korea APT #Stealth Malware
Daily CyberSecurity
North Korean APTs Upgrade Arsenal: Kimsuky Uses Stealthy HttpTroy, Lazarus Deploys New BLINDINGCAN RAT
Researchers at Gen Threat Labs have identified two new toolsets in active use by North Korean state-sponsored groups, underscoring the regime’s continued investment in advanced cyber-espionage and…
⤷ Title: Kinsing Cryptominer Exploits Apache ActiveMQ RCE (CVE-2023-46604), Adds Sharpire Backdoor for Multi-Stage Intrusion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:18:46 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ActiveMQ #Cobalt Strike #Cross_Platform #cryptominer #CVE_2023_46604 #Kinsing #rce #Sharpire
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:18:46 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ActiveMQ #Cobalt Strike #Cross_Platform #cryptominer #CVE_2023_46604 #Kinsing #rce #Sharpire
Daily CyberSecurity
Kinsing Cryptominer Exploits Apache ActiveMQ RCE (CVE-2023-46604), Adds Sharpire Backdoor for Multi-Stage Intrusion
ASEC confirmed Kinsing is exploiting Apache ActiveMQ RCE (CVE-2023-46604) to deploy XMRig cryptominer. The group now integrates Sharpire, Cobalt Strike, and Meterpreter for advanced post-exploitation.
⤷ Title: Open-Source AdaptixC2 Hacking Framework Adopted by Russian Cybercriminals and Akira Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:12:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #Akira ransomware #CountLoader #post_exploitation #RaaS #red_teaming #Russian cybercrime
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:12:33 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #Akira ransomware #CountLoader #post_exploitation #RaaS #red_teaming #Russian cybercrime
Daily CyberSecurity
Open-Source AdaptixC2 Hacking Framework Adopted by Russian Cybercriminals and Akira Ransomware
Silent Push found AdaptixC2, an open-source pen-testing framework, is now used by Russian cybercriminals and Akira RaaS. The developer's Russian-language activity suggests strong ties to the threat ecosystem.
⤷ Title: Next-Gen Android Banking Trojan Hides in Digital ID App, Automates Crypto Wallet Theft and Evades Emulators
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:08:58 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Banking Trojan #anti_emulation #BankBot_YNRK #crypto wallet theft #JobScheduler #Southeast Asia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:08:58 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Services #Android Banking Trojan #anti_emulation #BankBot_YNRK #crypto wallet theft #JobScheduler #Southeast Asia
Daily CyberSecurity
Next-Gen Android Banking Trojan Hides in Digital ID App, Automates Crypto Wallet Theft and Evades Emulators
Cyfirma exposed Android/BankBot-YNRK, a Trojan cloning Indonesia’s Digital ID app to steal credentials and crypto assets. It uses anti-emulation checks and JobScheduler for persistent device takeover.
⤷ Title: Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
Daily CyberSecurity
Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
Cybereason exposed Tangerine Turkey, a VBScript worm that spreads via USB drives. It uses LOLBins (printui.exe) and Windows Defender exclusions to deploy the XMRig cryptominer for profit.
⤷ Title: Copyright Pivot: Getty Images Partners with Perplexity AI to Tackle Content Attribution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:36 +0000
════════════════════════
⌗ Tags: #Technology #AI Search #Attribution #content #copyright #Getty Images #Lawsuit #Licensing #Perplexity.ai
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:36 +0000
════════════════════════
⌗ Tags: #Technology #AI Search #Attribution #content #copyright #Getty Images #Lawsuit #Licensing #Perplexity.ai
Daily CyberSecurity
Copyright Pivot: Getty Images Partners with Perplexity AI to Tackle Content Attribution
Perplexity AI licenses Getty Images' visual archives to integrate visuals into search with proper attribution, marking a strategic shift in AI copyright battles.
⤷ Title: Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
Daily CyberSecurity
Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
Elastic patched a Critical EoP flaw (CVE-2025-37736) in ECE (v3.8.3/4.0.3) where the readonly user can create admin users and inject new API keys by bypassing authorization checks.
⤷ Title: Testing XSS in chatbot instances
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 23:54:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_attack
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 23:54:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_attack
Medium
Testing XSS in chatbot instances
Here’s a little tip for testing XSS in chatbot instances; when you inject an XSS payload as a user message and it doesn’t execute, don’t…
⤷ Title: The Digital Hoarder’s Dilemma: Why Your Backup Strategy Is Probably Broken (And How to Fix It)
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:14:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #programming #technology #privacy #hacking
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:14:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #programming #technology #privacy #hacking
Medium
The Digital Hoarder’s Dilemma: Why Your Backup Strategy Is Probably Broken (And How to Fix It)
A brutally honest look at why we’re all terrible at protecting our digital lives
⤷ Title: The Delicate and Destructive Art of the Side Project Graveyard
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:18:56 GMT
════════════════════════
⌗ Tags: #productivity #hacking #coding #side_project #technology
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:18:56 GMT
════════════════════════
⌗ Tags: #productivity #hacking #coding #side_project #technology
Medium
The Delicate and Destructive Art of the Side Project Graveyard
Nothing wrong with adding a few more bodies to the pile.
⤷ Title: Invisible Entry Points: Why DNS, Ports, and IP Hygiene Define Web Security
════════════════════════
𐀪 Author: Cybamatica
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:36:18 GMT
════════════════════════
⌗ Tags: #network_security #dns #infosec #cybersecurity #web_security
════════════════════════
𐀪 Author: Cybamatica
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:36:18 GMT
════════════════════════
⌗ Tags: #network_security #dns #infosec #cybersecurity #web_security
Medium
Invisible Entry Points: Why DNS, Ports, and IP Hygiene Define Web Security
When securing a website, many focus on the obvious security aspects such as HTTPS, regular updates, and reputable hosting providers. But…
⤷ Title: PortSwigger Labs: Server Side Request Forgery (SSRF) Writeup (ALL LABS)
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:56:41 GMT
════════════════════════
⌗ Tags: #burpsuite #penetration_testing #portswigger #web_application_security #cybersecurity
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:56:41 GMT
════════════════════════
⌗ Tags: #burpsuite #penetration_testing #portswigger #web_application_security #cybersecurity
Medium
PortSwigger Labs: Server Side Request Forgery (SSRF) Writeup (ALL LABS)
I. SSRF with blacklist-based input filter
⤷ Title: PortSwigger Labs: Prototype Pollution Writeup (All labs)
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:48:31 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_application_security #portswigger #cybersecurity #burpsuite
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:48:31 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_application_security #portswigger #cybersecurity #burpsuite
Medium
PortSwigger Labs: Prototype Pollution Writeup (All labs)
I. DOM XSS via client-side prototype pollution
⤷ Title: Ini Cara Gampang Bikin Sistem Jebol!
════════════════════════
𐀪 Author: Jadi Hacker
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:37:57 GMT
════════════════════════
⌗ Tags: #owasp #websecurity_testing #cybersecurity #penetration_testing #broken_access_control
════════════════════════
𐀪 Author: Jadi Hacker
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:37:57 GMT
════════════════════════
⌗ Tags: #owasp #websecurity_testing #cybersecurity #penetration_testing #broken_access_control
Medium
Ini Cara Gampang Bikin Sistem Jebol!
Untuk kalian yang ngaku pengen jadi hacker, pernah dengar istilah BAC atau Broken Access Control?