⤷ Title: Invisible Hijack: New Agent Session Smuggling Attack Forces AI to Buy Stock Silently
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:24:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #A2A Protocol #Agent Session Smuggling #AI security #Gemini #Multi_Agent Systems #Unauthorized Transactions #Unit 42
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:24:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #A2A Protocol #Agent Session Smuggling #AI security #Gemini #Multi_Agent Systems #Unauthorized Transactions #Unit 42
Penetration Testing Tools
Invisible Hijack: New Agent Session Smuggling Attack Forces AI to Buy Stock Silently
Unit 42 detailed "Agent Session Smuggling," where a malicious agent injects hidden commands to coerce client AIs into unauthorized actions, like buying stock.
⤷ Title: Kernel in a Browser: Linux Ported to WebAssembly Runs Directly in Chrome
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:22:33 +0000
════════════════════════
⌗ Tags: #Linux #Browsers #kernel #LLVM #Proof of Concept #Wasm #WebAssembly #WebAssembly System Interface
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:22:33 +0000
════════════════════════
⌗ Tags: #Linux #Browsers #kernel #LLVM #Proof of Concept #Wasm #WebAssembly #WebAssembly System Interface
Penetration Testing Tools
Kernel in a Browser: Linux Ported to WebAssembly Runs Directly in Chrome
A developer ported the Linux kernel to WebAssembly (WASM), allowing it to run in a web browser. The experimental build is a proof of concept for WASM's potential.
⤷ Title: Redemption Arc: ZeroAccess Botnet Architect Resurfaces as a Microsoft-Certified Developer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:21:01 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #Developer #kernel debugger #Maksim Samuistov #malware #white hat #YDbg #ZeroAccess
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:21:01 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #Developer #kernel debugger #Maksim Samuistov #malware #white hat #YDbg #ZeroAccess
Penetration Testing Tools
Redemption Arc: ZeroAccess Botnet Architect Resurfaces as a Microsoft-Certified Developer
The creator of the infamous ZeroAccess botnet has resurfaced, transforming into a legitimate dev and publishing the YDbg kernel debugger—now signed by Microsoft.
⤷ Title: Security Alert: Malware Counterfeit of Flyoobe Tool Targets Users Bypassing Windows 11 Checks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:18:39 +0000
════════════════════════
⌗ Tags: #Malware #Counterfeit #Flyoobe #malware #Security Alert #TPM bypass #Unauthenticated #Unsupported Hardware #Windows 11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:18:39 +0000
════════════════════════
⌗ Tags: #Malware #Counterfeit #Flyoobe #malware #Security Alert #TPM bypass #Unauthenticated #Unsupported Hardware #Windows 11
Penetration Testing Tools
Security Alert: Malware Counterfeit of Flyoobe Tool Targets Users Bypassing Windows 11 Checks
A counterfeit site is distributing a malicious version of Flyoobe, the Windows 11 bypass tool. The developer warns against downloading the utility from any source but GitHub.
⤷ Title: Global Espionage: China-Linked Storm-1849 Targets U.S. & European Cisco ASA Networks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:16:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #China #CISA #Cisco ASA #Cyber Espionage #Government #network security #Storm_1849 #Unit 42
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:16:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #China #CISA #Cisco ASA #Cyber Espionage #Government #network security #Storm_1849 #Unit 42
Penetration Testing Tools
Global Espionage: China-Linked Storm-1849 Targets U.S. & European Cisco ASA Networks
China-linked Storm-1849 is aggressively exploiting Cisco ASA vulnerabilities globally, targeting U.S. and European gov networks. CISA issued an emergency patching directive.
⤷ Title: Code Antivirus: OpenAI Unveils Aardvark AI to Autonomously Find and Fix Software Vulnerabilities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:15:32 +0000
════════════════════════
⌗ Tags: #Technology #Aardvark #AI security #Code Auditing #CodeMender #DevSecOps #GPT_5 #OpenAI #vulnerability management
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:15:32 +0000
════════════════════════
⌗ Tags: #Technology #Aardvark #AI security #Code Auditing #CodeMender #DevSecOps #GPT_5 #OpenAI #vulnerability management
Penetration Testing Tools
Code Antivirus: OpenAI Unveils Aardvark AI to Autonomously Find and Fix Software Vulnerabilities
OpenAI launched Aardvark, a GPT-5 powered agent that autonomously detects, reproduces, and generates fixes for software vulnerabilities in real time.
⤷ Title: The Shrink Ray: Developer Runs Windows 7 at a Record-Low 69 Megabytes
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:09:43 +0000
════════════════════════
⌗ Tags: #Windows #Minimalism #OS Optimization #Proof of Concept #System Reduction #Tiny11 #Ultra_Compact #Windows 7
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:09:43 +0000
════════════════════════
⌗ Tags: #Windows #Minimalism #OS Optimization #Proof of Concept #System Reduction #Tiny11 #Ultra_Compact #Windows 7
Penetration Testing Tools
The Shrink Ray: Developer Runs Windows 7 at a Record-Low 69 Megabytes
A developer managed to shrink a fully bootable Windows 7 copy to 69MB—smaller than a mobile app. The feat demonstrates the limits of OS minimalism.
⤷ Title: Tap-and-Steal: New NFC Banking Malware Exploits Android’s HCE for Ghost Payments
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Android Security #banking trojan #Contactless Payment #Eastern Europe #EMV #HCE #Mobile fraud #NFC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:07:58 +0000
════════════════════════
⌗ Tags: #Malware #Android Security #banking trojan #Contactless Payment #Eastern Europe #EMV #HCE #Mobile fraud #NFC
Penetration Testing Tools
Tap-and-Steal: New NFC Banking Malware Exploits Android’s HCE for Ghost Payments
A surge of 760+ Android apps in Eastern Europe use NFC relay/HCE mechanisms to bypass payment security and execute fraudulent contactless transactions.
⤷ Title: CISA Warning: Linux Kernel Bug (CVE-2024-1086) Actively Exploited by Ransomware for Root Access
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:06:07 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability #CISA KEV #CVE_2024_1086 #Linux Kernel #Netfilter #privilege escalation #ransomware #use_after_free
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:06:07 +0000
════════════════════════
⌗ Tags: #Linux #Vulnerability #CISA KEV #CVE_2024_1086 #Linux Kernel #Netfilter #privilege escalation #ransomware #use_after_free
Penetration Testing Tools
CISA Warning: Linux Kernel Bug (CVE-2024-1086) Actively Exploited by Ransomware for Root Access
CISA confirms active exploitation of Linux kernel flaw (CVE-2024-1086) for root access via ransomware. The 10-year-old bug affects most major Linux distributions.
⤷ Title: Data Leak Flaw: Critical Bug Lets Attackers Trick Claude AI Into Exfiltrating User Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:03:12 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #AI Vulnerability #Anthropic #Claude #cybersecurity #Data Exfiltration #HackerOne #Prompt Injection #Sandbox
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:03:12 +0000
════════════════════════
⌗ Tags: #Data Leak #Vulnerability #AI Vulnerability #Anthropic #Claude #cybersecurity #Data Exfiltration #HackerOne #Prompt Injection #Sandbox
Penetration Testing Tools
Data Leak Flaw: Critical Bug Lets Attackers Trick Claude AI Into Exfiltrating User Data
A critical flaw allows indirect prompt injection to trick Claude into exfiltrating user data via its File API by substituting an attacker's access key. Anthropic warns users.
⤷ Title: New Threat Landscape: AI Browsers Create Agentic Vulnerabilities & Amplified Data Risk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:01:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Agentic AI #AI Browsers #browser security #ChatGPT Atlas #data leak #Perplexity Comet #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 04:01:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Agentic AI #AI Browsers #browser security #ChatGPT Atlas #data leak #Perplexity Comet #zero_day
Penetration Testing Tools
New Threat Landscape: AI Browsers Create Agentic Vulnerabilities & Amplified Data Risk
AI browsers like Edge Copilot & ChatGPT Atlas create new risks. Researchers warn agentic automation amplifies data theft via hidden instructions and zero-day vulnerabilities.
⤷ Title: AI Compute Race: Microsoft Secures $9.7 Billion GPU Deal with IREN for Cloud Expansion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:33:02 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Azure #Cloud Compute #Data Center #IREN #Microsoft #Nscale #NVIDIA GB300
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:33:02 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Azure #Cloud Compute #Data Center #IREN #Microsoft #Nscale #NVIDIA GB300
Daily CyberSecurity
AI Compute Race: Microsoft Secures $9.7 Billion GPU Deal with IREN for Cloud Expansion
Microsoft signed a 5-year, $9.7B deal with IREN for NVIDIA GB300 GPU compute capacity, part of a strategy to meet surging global demand for its Azure AI services.
⤷ Title: Cloud Wars: OpenAI Signs $38 Billion Computing Deal with AWS, Ending Microsoft Exclusivity
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:27:59 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Amazon #Anthropic #AWS #Cloud Computing #Graviton #Microsoft #OpenAI #Sam Altman
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:27:59 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Amazon #Anthropic #AWS #Cloud Computing #Graviton #Microsoft #OpenAI #Sam Altman
Daily CyberSecurity
Cloud Wars: OpenAI Signs $38 Billion Computing Deal with AWS, Ending Microsoft Exclusivity
OpenAI signed a $38B deal with AWS for cloud computing infrastructure, diversifying its resources after ending exclusivity with Microsoft. AWS gains a major AI client.
⤷ Title: Streamlined? Microsoft Strips Critical Info from Windows Update Names, Causing IT Backlash
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:23:45 +0000
════════════════════════
⌗ Tags: #Windows #IT Administration #KB5065789 #Microsoft #naming convention #readability #Windows Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:23:45 +0000
════════════════════════
⌗ Tags: #Windows #IT Administration #KB5065789 #Microsoft #naming convention #readability #Windows Update
Daily CyberSecurity
Streamlined? Microsoft Strips Critical Info from Windows Update Names, Causing IT Backlash
Microsoft is simplifying Windows Update names by removing OS version, date, and architecture—a change criticized by admins for degrading readability and context.
⤷ Title: The 69 MB Challenge: Developer Strips Windows 7 to Its Bare Minimum—And It Still Boots
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:17:13 +0000
════════════════════════
⌗ Tags: #Windows #Minimalism #OS Optimization #PC Modding #proof_of_concept #System Reduction #Tiny11 #Windows 7
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:17:13 +0000
════════════════════════
⌗ Tags: #Windows #Minimalism #OS Optimization #PC Modding #proof_of_concept #System Reduction #Tiny11 #Windows 7
Daily CyberSecurity
The 69 MB Challenge: Developer Strips Windows 7 to Its Bare Minimum—And It Still Boots
Developer @XenoPanther created a Windows 7 build that occupies just 69 MB. The ultra-compact OS successfully boots but is primarily a fascinating proof of concept.
⤷ Title: Access Denied: Microsoft Authenticator to Purge Entra ID Credentials on Rooted Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:13:20 +0000
════════════════════════
⌗ Tags: #Technology #Azure AD #enterprise #Entra ID #Jailbroken #MFA #Microsoft Authenticator #Rooted #security policy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:13:20 +0000
════════════════════════
⌗ Tags: #Technology #Azure AD #enterprise #Entra ID #Jailbroken #MFA #Microsoft Authenticator #Rooted #security policy
Daily CyberSecurity
Access Denied: Microsoft Authenticator to Purge Entra ID Credentials on Rooted Devices
Microsoft Authenticator will purge Entra ID credentials from jailbroken/rooted devices starting Feb 2026 to block token theft, enforcing security for enterprise accounts.
⤷ Title: Years Late: Apple Finally Launches Full Web-Based App Store Homepage with Search & Discovery
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:06:38 +0000
════════════════════════
⌗ Tags: #Technology #App Store #Apple #discovery #interface #ios #macOS #Search #web
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:06:38 +0000
════════════════════════
⌗ Tags: #Technology #App Store #Apple #discovery #interface #ios #macOS #Search #web
Daily CyberSecurity
Years Late: Apple Finally Launches Full Web-Based App Store Homepage with Search & Discovery
Apple unveiled a fully featured web-based App Store homepage with search, cross-platform toggles (iOS, macOS, watchOS), and a curated "Today" section.
⤷ Title: Passwordless Future: Microsoft Edge 142 Rolls Out Cross-Platform Passkey Sync
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:02:35 +0000
════════════════════════
⌗ Tags: #Technology #authentication #microsoft edge #Passkeys #Passwordless #security #Synchronization #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 03:02:35 +0000
════════════════════════
⌗ Tags: #Technology #authentication #microsoft edge #Passkeys #Passwordless #security #Synchronization #windows
Daily CyberSecurity
Passwordless Future: Microsoft Edge 142 Rolls Out Cross-Platform Passkey Sync
Edge v142.0 introduces cross-platform passkey sync, letting users reuse passkeys securely across devices with a PIN, enhancing passwordless authentication.
⤷ Title: Clarity Fix: iOS 26.1 Launches with Liquid Glass Tint Option & Camera Gesture Toggle
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 02:59:12 +0000
════════════════════════
⌗ Tags: #Technology #AirPods #Apple #Camera Gesture #Communication Safety #features #iOS 26.1 #iphone #Liquid Glass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 02:59:12 +0000
════════════════════════
⌗ Tags: #Technology #AirPods #Apple #Camera Gesture #Communication Safety #features #iOS 26.1 #iphone #Liquid Glass
Daily CyberSecurity
Clarity Fix: iOS 26.1 Launches with Liquid Glass Tint Option & Camera Gesture Toggle
Apple has officially released iOS 26.1, introducing two noteworthy new features. First, users can now disable the translucent “Liquid Glass” effect, increasing background opacity for improved clar…
⤷ Title: Model Pulled: Google Removes Gemma AI After Fabricating Defamatory Claims About U.S. Senator
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 02:50:33 +0000
════════════════════════
⌗ Tags: #Technology #AI Hallucination #Gemma #Generative AI #google #Google AI Studio #Marsha Blackburn #Misinformation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 02:50:33 +0000
════════════════════════
⌗ Tags: #Technology #AI Hallucination #Gemma #Generative AI #google #Google AI Studio #Marsha Blackburn #Misinformation
Daily CyberSecurity
Model Pulled: Google Removes Gemma AI After Fabricating Defamatory Claims About U.S. Senator
Gemma is an open-source artificial intelligence model developed by Google, available to all developers through Google AI Studio and other distribution channels. However, developers may now find it…
⤷ Title: SesameOp Backdoor Hijacks OpenAI Assistants API for Covert C2 and Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 02:32:40 +0000
════════════════════════
⌗ Tags: #Malware #.NET AppDomainManager #AI API Misuse #C2 Hijacking #Espionage #Microsoft DART #OpenAI API #SesameOp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 04 Nov 2025 02:32:40 +0000
════════════════════════
⌗ Tags: #Malware #.NET AppDomainManager #AI API Misuse #C2 Hijacking #Espionage #Microsoft DART #OpenAI API #SesameOp
Daily CyberSecurity
SesameOp Backdoor Hijacks OpenAI Assistants API for Covert C2 and Espionage
In an example of how threat actors are adapting to modern AI ecosystems, Microsoft’s Incident Response – Detection and Response Team (DART) has uncovered a sophisticated espionage-focused backdoor…