⤷ Title: Guía Avanzada de Penetration Testing en APIs (Parte 2) Explotación Práctica, Mitigación y Reporte…
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:02:04 GMT
════════════════════════
⌗ Tags: #api #technology #cybersecurity #hacking #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:02:04 GMT
════════════════════════
⌗ Tags: #api #technology #cybersecurity #hacking #bug_bounty
Medium
Guía Avanzada de Penetration Testing en APIs (Parte 2) Explotación Práctica, Mitigación y Reporte PoC
Metodología avanzada de pentesting en APIs. Incluye fases de explotación práctica (IDOR, Mass Assignment, SSRF, JWT), mitigación y reporte.
⤷ Title: Monthly Threat Actor Group Intelligence Report, October 2025
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:13:49 GMT
════════════════════════
⌗ Tags: #cyberattack #threat_intelligence #infosec #cybersecurity #hacking
════════════════════════
𐀪 Author: NSHC ThreatRecon Team
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:13:49 GMT
════════════════════════
⌗ Tags: #cyberattack #threat_intelligence #infosec #cybersecurity #hacking
Medium
Monthly Threat Actor Group Intelligence Report, October 2025
This is a summary of the activities of hacking groups (Threat Actor Groups) analyzed based on data and information
⤷ Title: Postman HTB Machine Walk-Through!
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:02:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #hack_the_box_walkthrough #ethical_hacking
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:02:17 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #hack_the_box_walkthrough #ethical_hacking
Medium
Postman HTB Machine Walk-Through!
So as with all HTB Labs, we’ll start off with our nmap scan see what ports are open and then further enumerate the ports that are..
⤷ Title: Why AI Gateways Will Be Non-Negotiable
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:22:14 GMT
════════════════════════
⌗ Tags: #information_security #api_gateway #cybersecurity #ai #api
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:22:14 GMT
════════════════════════
⌗ Tags: #information_security #api_gateway #cybersecurity #ai #api
Medium
Why AI Gateways Will Be Non-Negotiable
Large Language Models (LLMs) are no longer standalone tools. They’re evolving into multi-agent systems that plan, reason, and act together…
⤷ Title: Canada didn’t get breached because of a highly advanced cyber weapon.
════════════════════════
𐀪 Author: Abhinav pandey
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:21:20 GMT
════════════════════════
⌗ Tags: #canada #cybercrime #cybersecurity #ttp #cyberattack
════════════════════════
𐀪 Author: Abhinav pandey
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:21:20 GMT
════════════════════════
⌗ Tags: #canada #cybercrime #cybersecurity #ttp #cyberattack
Medium
🇨🇦 Canada didn’t get breached because of a highly advanced cyber weapon.
It happened because one weak point in an e-commerce database was enough.
⤷ Title: Ignite — Write-up (The un-intended way)
════════════════════════
𐀪 Author: CO0L7
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:16:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup
════════════════════════
𐀪 Author: CO0L7
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:16:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_writeup
Medium
Ignite — Write-up (The un-intended way)
Ignite is a very simple room. It starts of with a simple CMS that tells you its version and further details. From there we find public…
⤷ Title: How to Build Stronger Cybersecurity Through Smarter MDR Partnerships
════════════════════════
𐀪 Author: Scott Alldridge
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:01:35 GMT
════════════════════════
⌗ Tags: #cybersecurity
════════════════════════
𐀪 Author: Scott Alldridge
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 01:01:35 GMT
════════════════════════
⌗ Tags: #cybersecurity
Medium
How to Build Stronger Cybersecurity Through Smarter MDR Partnerships
In today’s complex digital landscape, cybersecurity is no longer confined to networks and firewalls. From credential-stuffing campaigns to…
⤷ Title: How Zero Trust and VisibleOps Are Revolutionizing Business Security with Scott Alldridge
════════════════════════
𐀪 Author: Scott Alldridge
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:49:11 GMT
════════════════════════
⌗ Tags: #cybersecurity_news #cybersecurity_awareness #business_security #cybersecurity
════════════════════════
𐀪 Author: Scott Alldridge
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:49:11 GMT
════════════════════════
⌗ Tags: #cybersecurity_news #cybersecurity_awareness #business_security #cybersecurity
Medium
How Zero Trust and VisibleOps Are Revolutionizing Business Security with Scott Alldridge
In an era where cyber threats evolve faster than ever, businesses can no longer rely on traditional security frameworks. The need for Zero…
⤷ Title: Offensive Security Intro
════════════════════════
𐀪 Author: Demegorash
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:36:41 GMT
════════════════════════
⌗ Tags: #red_team #cybersecurity #offensive_security
════════════════════════
𐀪 Author: Demegorash
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:36:41 GMT
════════════════════════
⌗ Tags: #red_team #cybersecurity #offensive_security
Medium
Offensive Security Intro
What is Offensive Security?
⤷ Title: Beyond Data at Rest and Data in Motion: Securing Data in Use with Confidential Computing
════════════════════════
𐀪 Author: ThamizhElango Natarajan
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:32:00 GMT
════════════════════════
⌗ Tags: #zero_trust #cloud_security #cybersecurity #confidential_computing
════════════════════════
𐀪 Author: ThamizhElango Natarajan
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:32:00 GMT
════════════════════════
⌗ Tags: #zero_trust #cloud_security #cybersecurity #confidential_computing
Medium
🔐 Beyond Data at Rest and Data in Motion: Securing Data in Use with Confidential Computing
🧠 Introduction
⤷ Title: One Click Away:
════════════════════════
𐀪 Author: Afolabi muhydeen olalekan
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:32:00 GMT
════════════════════════
⌗ Tags: #cyberattack #cybersecurity #ethical_hacking #phishing #data_privacy
════════════════════════
𐀪 Author: Afolabi muhydeen olalekan
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:32:00 GMT
════════════════════════
⌗ Tags: #cyberattack #cybersecurity #ethical_hacking #phishing #data_privacy
Medium
One Click Away:
How a Simple Email Nearly Compromised a Whole Network
⤷ Title: Pwn The Tron: 1 — vulnhub
════════════════════════
𐀪 Author: satoshi_nakamura
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:49:25 GMT
════════════════════════
⌗ Tags: #vulnhub #boot_to_root
════════════════════════
𐀪 Author: satoshi_nakamura
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:49:25 GMT
════════════════════════
⌗ Tags: #vulnhub #boot_to_root
Medium
Pwn The Tron: 1 — vulnhub
kali ini kita akan mengerjakan soal boot to root lagi, disini nama soal yang akan kita kerjakan ialah Pwn The Tron: 1. challenge ini…
⤷ Title: Why HTTPS Matters: The Real Reason TLS/SSL Exists
════════════════════════
𐀪 Author: Arfi Tutorials
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:02:05 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #ethical_hacking #networking #technology
════════════════════════
𐀪 Author: Arfi Tutorials
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:02:05 GMT
════════════════════════
⌗ Tags: #information_security #cybersecurity #ethical_hacking #networking #technology
Medium
Why HTTPS Matters: The Real Reason TLS/SSL Exists
Hello everyone! My name is Arfat Khan, and I run a YouTube channel called Arfi Tutorials. I am a bug bounty hunter, penetration tester, and…
⤷ Title: US Treasury Sanctions 8 North Koreans and 2 Banks for Laundering Crypto to Fund WMD Programs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:31:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Money Laundering #Cybercrime #DPRK Sanctions #IT Workers #North Korea #OFAC #WMD Funding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:31:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Money Laundering #Cybercrime #DPRK Sanctions #IT Workers #North Korea #OFAC #WMD Funding
Daily CyberSecurity
US Treasury Sanctions 8 North Koreans and 2 Banks for Laundering Crypto to Fund WMD Programs
OFAC sanctioned 8 individuals and 2 banks linked to North Korea for laundering millions in stolen crypto and IT earnings to fund Pyongyang's WMD and missile programs.
⤷ Title: OCI Fixes Container Escape Vulnerabilities in runc (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #container security #CVE_2025_31133 #docker #Kubernetes #OCI #privilege escalation #runc
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:26:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #container escape #container security #CVE_2025_31133 #docker #Kubernetes #OCI #privilege escalation #runc
Daily CyberSecurity
OCI Fixes Container Escape Vulnerabilities in runc (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881)
OCI patched three critical runc flaws allowing container escape and host DoS/RCE. Attackers exploit mount race conditions in maskedPaths and /dev/console bind-mounts. Update to v1.2.8+.
⤷ Title: Booking.com Phishing Campaign Hijacks Hotel Accounts to Deliver PureRAT via ClickFix Lure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:23:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #ClickFix #hospitality #MaaS #phishing #PureRAT #Remote Access Trojan #Sekoia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:23:50 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Booking.com #ClickFix #hospitality #MaaS #phishing #PureRAT #Remote Access Trojan #Sekoia
Daily CyberSecurity
Booking.com Phishing Campaign Hijacks Hotel Accounts to Deliver PureRAT via ClickFix Lure
Sekoia exposed a campaign exploiting compromised Booking.com/Expedia accounts to deliver PureRAT malware via a ClickFix lure. Attackers use authentic reservation details to steal guest credentials.
⤷ Title: High-Severity Cisco ISE Flaw (CVE-2025-20343) Allows Unauthenticated DoS via Crafted RADIUS Requests
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:19:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cisco ISE #Critical Vulnerability #CVE_2025_20343 #Denial of Service #NAC #Network Access Control #RADIUS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:19:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cisco ISE #Critical Vulnerability #CVE_2025_20343 #Denial of Service #NAC #Network Access Control #RADIUS
Daily CyberSecurity
High-Severity Cisco ISE Flaw (CVE-2025-20343) Allows Unauthenticated DoS via Crafted RADIUS Requests
Cisco patched a High-severity DoS flaw (CVE-2025-20343) in ISE that allows unauthenticated remote attackers to crash the server via crafted RADIUS requests. Disable the Reject setting as a workaround.
⤷ Title: DragonForce Ransomware Strikes Manufacturing Sector with Brute-Force, Exfiltrating Data Over SSH to Russian Host
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:12:11 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force #Darktrace #DragonForce #Manufacturing #openvas #RaaS #ransomware #SSH Exfiltration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:12:11 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force #Darktrace #DragonForce #Manufacturing #openvas #RaaS #ransomware #SSH Exfiltration
Daily CyberSecurity
DragonForce Ransomware Strikes Manufacturing Sector with Brute-Force, Exfiltrating Data Over SSH to Russian Host
Darktrace exposed a DragonForce RaaS attack on a manufacturer. The multi-phase intrusion used brute force and OpenVAS for recon, then exfiltrated data over SSH to a Russian-based malicious host.
⤷ Title: Amazon Fixes High-Severity Authentication Token Exposure in WorkSpaces Client for Linux (CVE-2025-12779)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:06:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Token #AWS #CVE_2025_12779 #DCV #Linux #privilege escalation #WorkSpaces Client
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:06:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Token #AWS #CVE_2025_12779 #DCV #Linux #privilege escalation #WorkSpaces Client
Daily CyberSecurity
Amazon Fixes High-Severity Authentication Token Exposure in WorkSpaces Client for Linux (CVE-2025-12779)
AWS patched a High-severity flaw (CVE-2025-12779) in the WorkSpaces client for Linux. A local user can extract DCV authentication tokens to hijack another user’s virtual desktop session. Update to v2025.0.
⤷ Title: New Cephalus Ransomware Uses Fake AES Keys and GoLang to Thwart Analysis
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #anti_analysis #Cephalus #Fake AES Key #Golang #ransomware #RDP Brute Force #VirtualLock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 00:00:57 +0000
════════════════════════
⌗ Tags: #Cybercriminals #anti_analysis #Cephalus #Fake AES Key #Golang #ransomware #RDP Brute Force #VirtualLock
Daily CyberSecurity
New Cephalus Ransomware Uses Fake AES Keys and GoLang to Thwart Analysis
ASEC exposed Cephalus, a Go-based RaaS group attacking RDP. The malware uses VirtualLock, XOR encryption, and a fake AES key pattern to severely complicate memory and forensic analysis.
⤷ Title: How Hacking for Free Made Me Employable
════════════════════════
𐀪 Author: Gavin K
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 03:49:21 GMT
════════════════════════
⌗ Tags: #red_team #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Gavin K
════════════════════════
ⴵ Time: Fri, 07 Nov 2025 03:49:21 GMT
════════════════════════
⌗ Tags: #red_team #bug_bounty #cybersecurity
Medium
How Hacking for Free Made Me Employable
tldr: bug bounty allowed me to start my career in offensive security early.