⤷ Title: 10 Successful Marketplaces Built on Sharetribe: Lessons Learned
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 09:33:41 +0000
════════════════════════
⌗ Tags: #Technology #Buisiness #Sharetribe
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 09:33:41 +0000
════════════════════════
⌗ Tags: #Technology #Buisiness #Sharetribe
Hackread
10 Successful Marketplaces Built on Sharetribe: Lessons Learned
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Cyber Deception: BUDA Framework Automates Realistic User Behavior to Trap Attackers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:29:12 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BUDA #cybersecurity #Deception Operations #HoneyPot #Red Team #Security Framework #Simulation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:29:12 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BUDA #cybersecurity #Deception Operations #HoneyPot #Red Team #Security Framework #Simulation
Penetration Testing Tools
Cyber Deception: BUDA Framework Automates Realistic User Behavior to Trap Attackers
The BUDA framework enhances deception operations by automating the simulation of realistic user behaviors and profiles within decoy environments to mislead attackers.
⤷ Title: AI Backdoor: SesameOp Malware Uses OpenAI API as Covert Command-and-Control Channel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:10:48 +0000
════════════════════════
⌗ Tags: #Malware #C2 #Command and Control #cybersecurity #malware #Microsoft #OpenAI Assistants API #SesameOp #threat intelligence
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:10:48 +0000
════════════════════════
⌗ Tags: #Malware #C2 #Command and Control #cybersecurity #malware #Microsoft #OpenAI Assistants API #SesameOp #threat intelligence
Penetration Testing Tools
AI Backdoor: SesameOp Malware Uses OpenAI API as Covert Command-and-Control Channel
Microsoft uncovered SesameOp, a malware using the OpenAI Assistants API for covert C2. It exploits a legitimate cloud platform to evade detection and maintain stealthy access.
⤷ Title: China Chip Power: Huawei Unveils Qingyun Desktops with New Kirin 9000X & Linux OS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:09:22 +0000
════════════════════════
⌗ Tags: #Technology #Chinese market #Desktop PC #Galaxy Kylin #HiSilicon #Huawei #Kirin 9000X #Qingyun #Tongxin UOS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:09:22 +0000
════════════════════════
⌗ Tags: #Technology #Chinese market #Desktop PC #Galaxy Kylin #HiSilicon #Huawei #Kirin 9000X #Qingyun #Tongxin UOS
Penetration Testing Tools
China Chip Power: Huawei Unveils Qingyun Desktops with New Kirin 9000X & Linux OS
Huawei unveiled Qingyun W515y/W585y desktops for the Chinese market, featuring the unreleased Kirin 9000X chip and running Tongxin UOS or Galaxy Kylin Linux OS.
⤷ Title: Digital Highwaymen: Hackers Use RMM Tools to Hijack Physical Cargo Shipments
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:05:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cargo Hijacking #Cargo Theft #cybercrime #Logistics #Proofpoint #Remote Management #RMM #Social Engineering #Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:05:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cargo Hijacking #Cargo Theft #cybercrime #Logistics #Proofpoint #Remote Management #RMM #Social Engineering #Supply Chain
Penetration Testing Tools
Digital Highwaymen: Hackers Use RMM Tools to Hijack Physical Cargo Shipments
Criminals are exploiting logistics platforms with RMM tools (ScreenConnect, SimpleHelp) to win freight tenders and physically reroute/hijack cargo shipments in North America.
⤷ Title: DeFi Disaster: Hackers Steal $120 Million in ETH from Balancer Protocol in Massive Breach
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:02:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Balancer #crypto hack #cybersecurity #DeFi #Ethereum #Liquidity Pool #North Korea #Security Audit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 04:02:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Balancer #crypto hack #cybersecurity #DeFi #Ethereum #Liquidity Pool #North Korea #Security Audit
Penetration Testing Tools
DeFi Disaster: Hackers Steal $120 Million in ETH from Balancer Protocol in Massive Breach
The Balancer DeFi protocol was breached, losing over $120 million in crypto (mostly ETH) due to an access control flaw. Affected liquidity pools have been suspended.
⤷ Title: Android Debut: OpenAI Launches Sora AI Video Generator with Audio Mixing & Voiceover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 08:24:52 +0000
════════════════════════
⌗ Tags: #Technology #AI video #android #Audio Mixing #Mobile App #OpenAI #Sora #Video Generation #Voiceover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 08:24:52 +0000
════════════════════════
⌗ Tags: #Technology #AI video #android #Audio Mixing #Mobile App #OpenAI #Sora #Video Generation #Voiceover
Daily CyberSecurity
Android Debut: OpenAI Launches Sora AI Video Generator with Audio Mixing & Voiceover
OpenAI officially launched Sora for Android, allowing users to create 30 free AI-generated videos daily. The app includes audio mixing and voiceover features.
⤷ Title: Chromebook Killer? Apple Prepares Affordable MacBook Air (J700) for 2026 Launch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:28:12 +0000
════════════════════════
⌗ Tags: #Technology #A_Series Chip #Apple #Budget Laptop #Chromebook #J700 #LCD Display #MacBook Air #Mark Gurman
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:28:12 +0000
════════════════════════
⌗ Tags: #Technology #A_Series Chip #Apple #Budget Laptop #Chromebook #J700 #LCD Display #MacBook Air #Mark Gurman
Daily CyberSecurity
Chromebook Killer? Apple Prepares Affordable MacBook Air (J700) for 2026 Launch
Apple is preparing an affordable MacBook model (codenamed J700) with a 12-inch LCD screen & A-series chip to compete with Chromebooks. Expected launch in 2026.
⤷ Title: Orbital AI: Google Unveils Project Suncatcher to Launch TPU Data Centers into Space
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:22:37 +0000
════════════════════════
⌗ Tags: #Technology #AI #Data Center #google #Planet Labs #Project Suncatcher #satellite #Space Computing #TPU
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:22:37 +0000
════════════════════════
⌗ Tags: #Technology #AI #Data Center #google #Planet Labs #Project Suncatcher #satellite #Space Computing #TPU
Daily CyberSecurity
Orbital AI: Google Unveils Project Suncatcher to Launch TPU Data Centers into Space
Google announced Project Suncatcher: an ambitious plan to launch TPU-equipped satellites to perform AI computing in space, harnessing limitless solar power and low temperatures.
⤷ Title: Dev Oversight: Apple Accidentally Leaked Entire App Store Web Source Code via SourceMap
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:15:54 +0000
════════════════════════
⌗ Tags: #Data Leak #App Store #Apple #Data Exposure #Procedural Lapse #source code #SourceMap #Svelte #TypeScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:15:54 +0000
════════════════════════
⌗ Tags: #Data Leak #App Store #Apple #Data Exposure #Procedural Lapse #source code #SourceMap #Svelte #TypeScript
Daily CyberSecurity
Dev Oversight: Apple Accidentally Leaked Entire App Store Web Source Code via SourceMap
Apple failed to disable SourceMap in its new App Store web version, inadvertently leaking the entire Svelte/TypeScript front-end codebase to the public.
⤷ Title: Five-Year Support: Ubuntu Unveils Final Release Schedule for 26.04 LTS Edition
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:09:50 +0000
════════════════════════
⌗ Tags: #Linux #Feature Freeze #GNOME 50 #LTS #Release Schedule #Ubuntu #Ubuntu 26.04
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 03:09:50 +0000
════════════════════════
⌗ Tags: #Linux #Feature Freeze #GNOME 50 #LTS #Release Schedule #Ubuntu #Ubuntu 26.04
Daily CyberSecurity
Five-Year Support: Ubuntu Unveils Final Release Schedule for 26.04 LTS Edition
Ubuntu 26.04 LTS release schedule finalized: Feature freeze Feb 19, 2026; final stable release April 23, 2026. LTS users must wait until Aug 6, 2026, to upgrade.
⤷ Title: False Alarm: Microsoft Fixes Bug Incorrectly Warning Windows 10 LTSC & ESU Users That Support Ended
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 02:54:52 +0000
════════════════════════
⌗ Tags: #Windows #end of support #ESU #KB5066791 #LTSC #Microsoft Bug #Windows 10 #Windows Update
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 02:54:52 +0000
════════════════════════
⌗ Tags: #Windows #end of support #ESU #KB5066791 #LTSC #Microsoft Bug #Windows 10 #Windows Update
Daily CyberSecurity
False Alarm: Microsoft Fixes Bug Incorrectly Warning Windows 10 LTSC & ESU Users That Support Ended
Microsoft fixed a bug incorrectly showing Windows 10 LTSC and ESU users that support ended. A cloud-based rollback corrects the policy automatically via the internet.
⤷ Title: Finally Independent: WhatsApp Launches Native Apple Watch App with Voice Messages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 02:48:15 +0000
════════════════════════
⌗ Tags: #Technology #Apple Watch #End_to_End Encryption #Meta #Native App #Voice Messages #watchOS 10 #WhatsApp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 02:48:15 +0000
════════════════════════
⌗ Tags: #Technology #Apple Watch #End_to_End Encryption #Meta #Native App #Voice Messages #watchOS 10 #WhatsApp
Daily CyberSecurity
Finally Independent: WhatsApp Launches Native Apple Watch App with Voice Messages
Meta launched a native WhatsApp app for Apple Watch (watchOS 10+). Users can now view full messages, send voice notes, and use E2EE without the iPhone.
⤷ Title: Critical CVE-2025-11749 Flaw in AI Engine Plugin Exposes WordPress Sites to Full Compromise
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 02:04:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #AI Engine #Authentication Bypass #CVE_2025_11749 #MCP #privilege escalation #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 02:04:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #AI Engine #Authentication Bypass #CVE_2025_11749 #MCP #privilege escalation #wordpress
Daily CyberSecurity
Critical CVE-2025-11749 Flaw in AI Engine Plugin Exposes WordPress Sites to Full Compromise
A Critical (CVSS 9.8) Auth Bypass in AI Engine is actively exploited. The flaw exposes the MCP bearer token via the REST API when No-Auth URL is enabled, allowing admin takeover.
⤷ Title: Stealthy Recon: Master Passive Information Gathering for Pentesters Step-by-Step
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 07:25:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #hacking #penetration_testing
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 07:25:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #bug_bounty #hacking #penetration_testing
Medium
Stealthy Recon: Master Passive Information Gathering for Pentesters Step-by-Step
✨ Link for the full article in the first comment
⤷ Title: ♂️ Session Zombies: The Forgotten Refresh Tokens That Never Die
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 07:11:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #ai #infosec #cybersecurity #information_security
════════════════════════
𐀪 Author: Narendar Battula (nArEn)
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 07:11:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #ai #infosec #cybersecurity #information_security
Medium
🧟♂️ Session Zombies: The Forgotten Refresh Tokens That Never Die
How stale refresh tokens quietly keep attackers (and bugs) logged in — and what to do about it
⤷ Title: From Intent to Native Code: Exploiting a WebView’s JavascriptInterface via XSS
════════════════════════
𐀪 Author: Mohamed hamdy
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:50:41 GMT
════════════════════════
⌗ Tags: #mobile_pentesting #mobile_app_development #android #offensive_security #bug_bounty
════════════════════════
𐀪 Author: Mohamed hamdy
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:50:41 GMT
════════════════════════
⌗ Tags: #mobile_pentesting #mobile_app_development #android #offensive_security #bug_bounty
Medium
From Intent to Native Code: Exploiting a WebView’s JavascriptInterface via XSS
🙋♂️ About Me
⤷ Title: How I Stole an AI’s Diary and Found All Its Secrets
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:22:50 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #money #cybersecurity #bug_bounty #infosec
════════════════════════
𐀪 Author: Iski
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:22:50 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #money #cybersecurity #bug_bounty #infosec
Medium
How I Stole an AI’s Diary and Found All Its Secrets 📖🤖
Hey there!😁
⤷ Title: How I Found My First Web Bug as a Beginner
════════════════════════
𐀪 Author: Shaikh Minhaz
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:16:52 GMT
════════════════════════
⌗ Tags: #beginner #bug_bounty #vulnerability #cybersecurity #how_to
════════════════════════
𐀪 Author: Shaikh Minhaz
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:16:52 GMT
════════════════════════
⌗ Tags: #beginner #bug_bounty #vulnerability #cybersecurity #how_to
Medium
How I Found My First Web Bug as a Beginner 🔥
Yes — your first real bug is closer than you think. Not some textbook nonsense, not a contrived lab — a bug on a live program that was…
⤷ Title: Internal Cache Poisoning: How Multi-Layer Caches Can Be Exploited for Stored XSS
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:04:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #x_forwarded_host #stored_xss #web_cache_poisoning #internal_cache_poisoning
════════════════════════
𐀪 Author: Bash Overflow
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 06:04:09 GMT
════════════════════════
⌗ Tags: #bug_bounty #x_forwarded_host #stored_xss #web_cache_poisoning #internal_cache_poisoning
Medium
Internal Cache Poisoning: How Multi-Layer Caches Can Be Exploited for Stored XSS
Learn how inconsistent cache key handling across layers can expose modern web applications to hidden injection risks.
⤷ Title: Meta bug bounty — One Last Spark AR RCE
════════════════════════
𐀪 Author: Fady Othman
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 05:22:53 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Fady Othman
════════════════════════
ⴵ Time: Wed, 05 Nov 2025 05:22:53 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bug_bounty_writeup #bug_bounty
Medium
Meta bug bounty — One Last Spark AR RCE
I highly recommend that you read my previous Spark AR write up, while the two bugs are not related, the other post contains more…