⤷ Title: Day 10: Network Security Essentials — Firewalls, IDS/IPS, Access Control & Common Attacks
════════════════════════
𐀪 Author: HackTrace
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 22:31:02 GMT
════════════════════════
⌗ Tags: #hacking #firewall #networking #cybersecurity
════════════════════════
𐀪 Author: HackTrace
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 22:31:02 GMT
════════════════════════
⌗ Tags: #hacking #firewall #networking #cybersecurity
Medium
Day 10: Network Security Essentials — Firewalls, IDS/IPS, Access Control & Common Attacks
Introduction
⤷ Title: Apache Tomcat’s CVE Verification on 8.5: What Three New CVEs Reveal About Open Source Security
════════════════════════
𐀪 Author: Jared Rhodes
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:55:13 GMT
════════════════════════
⌗ Tags: #open_source #cybersecurity #open_source_security
════════════════════════
𐀪 Author: Jared Rhodes
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:55:13 GMT
════════════════════════
⌗ Tags: #open_source #cybersecurity #open_source_security
Medium
Apache Tomcat’s CVE Verification on 8.5: What Three New CVEs Reveal About Open Source Security
Something interesting happened in the Tomcat ecosystem on October 27, 2025 that hasn’t ever happened before.
⤷ Title: How can they trick you & track you with a link or a file….& not only….
════════════════════════
𐀪 Author: Snooptsz
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:51:25 GMT
════════════════════════
⌗ Tags: #tech #internet #cybersecurity #technology
════════════════════════
𐀪 Author: Snooptsz
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:51:25 GMT
════════════════════════
⌗ Tags: #tech #internet #cybersecurity #technology
Medium
How can they trick you & track you with a link or a file….& not only….
Tips, Tools & Techniques used by Hackers, Scammers, & Coworkers to Track & Exploit Files, Links, & More… yet, How to Avoid Falling for…
⤷ Title: CyCTF 2025 Quals | DokDok | Super Detailed Approach
════════════════════════
𐀪 Author: 0xDolphin
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:45:42 GMT
════════════════════════
⌗ Tags: #cyctf #ctf #forensics #cybersecurity #docker_forensics
════════════════════════
𐀪 Author: 0xDolphin
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:45:42 GMT
════════════════════════
⌗ Tags: #cyctf #ctf #forensics #cybersecurity #docker_forensics
Medium
CyCTF 2025 Quals | DokDok | Super Detailed Approach
Hello guys, this is Mousa AKA 0xDolphin. I took part with my amazing team Ast3roids in CyCTF 2025 — hosted by the amazing CyShield…
⤷ Title: مرحلة جديدة
════════════════════════
𐀪 Author: Maria Writes
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:19:09 GMT
════════════════════════
⌗ Tags: #arabic #bilingual #cybersecurity #cyber_security_awareness
════════════════════════
𐀪 Author: Maria Writes
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 23:19:09 GMT
════════════════════════
⌗ Tags: #arabic #bilingual #cybersecurity #cyber_security_awareness
Medium
مَرحَلَة جَدِيدَة
محاولة لطيفة باللغة العربية - إنتاجي الأول!
⤷ Title: Applying the Principle of Least Privilege with AWS IAM: A Hands-On Project
════════════════════════
𐀪 Author: Okeke Jehohanan Ginika
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 22:49:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #aws_iam #aws #cloud_computing #iam_roles
════════════════════════
𐀪 Author: Okeke Jehohanan Ginika
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 22:49:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #aws_iam #aws #cloud_computing #iam_roles
Medium
Applying the Principle of Least Privilege with AWS IAM: A Hands-On Project
When I started learning about cloud computing, one principle stood out to me, the Principle of Least Privilege. It simply means: give…
⤷ Title: GZR Observer — Global Daily — India Perspective Nov 10, 2025
════════════════════════
𐀪 Author: Ninad Bhamburdekar
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 22:45:53 GMT
════════════════════════
⌗ Tags: #syria #cybersecurity #pakistan #russia #china
════════════════════════
𐀪 Author: Ninad Bhamburdekar
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 22:45:53 GMT
════════════════════════
⌗ Tags: #syria #cybersecurity #pakistan #russia #china
Medium
GZR Observer — Global Daily — India Perspective Nov 10, 2025
GZR Observer — Global Daily — India Perspective Nov 10, 2025 Russia Dismantles Pakistan’s Intelligence Spy Ring Targeting Air Defence Technology United States Domestic Politics And …
⤷ Title: SuiteCRM SQL Injection Flaws (CVE-2025-64492, CVE-2025-64493) Expose Customer Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:38:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CRM Security #CVE_2025_64492 #graphql #sql injection #SuiteCRM #Time_Based SQLi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:38:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CRM Security #CVE_2025_64492 #graphql #sql injection #SuiteCRM #Time_Based SQLi
Daily CyberSecurity
SuiteCRM SQL Injection Flaws (CVE-2025-64492, CVE-2025-64493) Expose Customer Data
The maintainers of SuiteCRM, the popular open-source customer relationship management (CRM) platform, have released an urgent security update addressing two significant SQL injection vulnerabiliti…
⤷ Title: Australia Joins US, Slaps Sanctions on North Korean Cybercriminals for Funding WMD Programs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:36:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Australia #Cryptocurrency Theft #Cybercrime #Financial Crime #Lazarus Group #North Korea #sanctions #WMD
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:36:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Australia #Cryptocurrency Theft #Cybercrime #Financial Crime #Lazarus Group #North Korea #sanctions #WMD
Daily CyberSecurity
Australia Joins US, Slaps Sanctions on North Korean Cybercriminals for Funding WMD Programs
Australia imposed sanctions and travel bans on four entities and one individual for engaging in cybercrime to fund North Korea's WMD and missile programs. The regime stole $1.9B in crypto in 2024.
⤷ Title: Telegram-Powered Phishing Campaign Targets European Businesses Using HTML Attachments to Steal Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:33:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #anti_forensics #Credential Theft #Cyble #HTML Attachment #Obfuscation #phishing #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:33:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #anti_forensics #Credential Theft #Cyble #HTML Attachment #Obfuscation #phishing #Telegram C2
Daily CyberSecurity
Telegram-Powered Phishing Campaign Targets European Businesses Using HTML Attachments to Steal Credentials
CRIL exposed fileless phishing using malicious HTML attachments. Credentials are stolen via a fake Adobe login and instantly exfiltrated to Telegram bots, bypassing traditional domain filters.
⤷ Title: Critical Devolutions Server Flaw (CVE-2025-12485, CVSS 9.4) Allows User Impersonation via Pre-MFA Cookie Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:29:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Credential Management #Critical Vulnerability #CVE_2025_12485 #Devolutions Server #PAM #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:29:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Credential Management #Critical Vulnerability #CVE_2025_12485 #Devolutions Server #PAM #privilege escalation
Daily CyberSecurity
Critical Devolutions Server Flaw (CVE-2025-12485, CVSS 9.4) Allows User Impersonation via Pre-MFA Cookie Hijacking
Devolutions patched two flaws in Devolutions Server: A Critical (CVSS 9.4) Auth Bypass allows user impersonation via pre-MFA cookie replay, and another flaw leaks plaintext passwords to view-only users.
⤷ Title: Critical WatchGuard Firebox Flaw (CVE-2025-59396, CVSS 9.8) Allows Unauthenticated Admin SSH Takeover via Default Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:25:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59396 #default credentials #Firebox #misconfiguration #network_security #ssh #WatchGuard
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:25:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59396 #default credentials #Firebox #misconfiguration #network_security #ssh #WatchGuard
Daily CyberSecurity
Critical WatchGuard Firebox Flaw (CVE-2025-59396, CVSS 9.8) Allows Unauthenticated Admin SSH Takeover via Default Credentials
A Critical (CVSS 9.8) flaw (CVE-2025-59396) in WatchGuard Firebox allows unauthenticated remote root access via SSH on port 4118 using default credentials (admin:readwrite). Patch immediately.
⤷ Title: Critical GE Vernova ICS Flaw (CVE-2025-3222, CVSS 9.3) Allows Authentication Bypass in Smallworld Master File Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:22:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_3222 #GE Vernova #ICS #OT Security #Smallworld
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:22:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_3222 #GE Vernova #ICS #OT Security #Smallworld
Daily CyberSecurity
Critical GE Vernova ICS Flaw (CVE-2025-3222, CVSS 9.3) Allows Authentication Bypass in Smallworld Master File Server
GE Vernova patched a Critical Auth Bypass flaw (CVE-2025-3222) in Smallworld Master File Server. The flaw could allow users with system knowledge to circumvent authentication. Update immediately.
⤷ Title: North Korea’s KONNI APT Hijacks Google Find Hub to Remotely Wipe and Track South Korean Android Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:16:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Find Hub Abuse #Google Account #KakaoTalk #KONNI APT #North Korea #Remote Wipe #social engineering #south korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:16:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Find Hub Abuse #Google Account #KakaoTalk #KONNI APT #North Korea #Remote Wipe #social engineering #south korea
Daily CyberSecurity
North Korea's KONNI APT Hijacks Google Find Hub to Remotely Wipe and Track South Korean Android Devices
North Korea's KONNI APT is exploiting stolen Google accounts and the Find Hub service to remotely wipe South Korean Android devices for data destruction and surveillance, then spreading malware via KakaoTalk.
⤷ Title: Critical Calibre Flaw (CVE-2025-64486, CVSS 9.3) Allows RCE via Malicious FB2 E-book
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Calibre #CVE_2025_64486 #E_book Manager #FB2 #FictionBook #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Calibre #CVE_2025_64486 #E_book Manager #FB2 #FictionBook #rce
Daily CyberSecurity
Critical Calibre Flaw (CVE-2025-64486, CVSS 9.3) Allows RCE via Malicious FB2 E-book
A Critical (CVSS 9.3) RCE flaw (CVE-2025-64486) in Calibre allows arbitrary code execution when a user views or converts a malicious FB2 e-book due to unsafe filename handling. Update to v8.14.0.
⤷ Title: Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
Daily CyberSecurity
Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
ENKI exposed a Lazarus Group espionage campaign targeting aerospace/defense firms. The new Comebacker variant uses malicious Word macros and ChaCha20/AES to deliver a memory-resident backdoor.
⤷ Title: DragonForce Ransomware Evolves with BYOVD to Kill EDR and Fixes Encryption Flaws in Conti V3 Codebase
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:00:29 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Conti V3 #cybersecurity #DragonForce #EDR Bypass #MinGW #RaaS #vulnerable driver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:00:29 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Conti V3 #cybersecurity #DragonForce #EDR Bypass #MinGW #RaaS #vulnerable driver
Daily CyberSecurity
DragonForce Ransomware Evolves with BYOVD to Kill EDR and Fixes Encryption Flaws in Conti V3 Codebase
The Acronis Threat Research Unit (TRU) has identified a new DragonForce ransomware variant that showcases a dramatic evolution in both technical sophistication and organizational structure. The up…
⤷ Title: Vulnerabilidades en GraphQL API: Guía de Explotación, Descubrimiento y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #bug_bounty #technology #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #bug_bounty #technology #hacking
Medium
Vulnerabilidades en GraphQL API: Guía de Explotación, Descubrimiento y Mitigación
Guía completa sobre vulnerabilidades en APIs GraphQL: descubrimiento de endpoints, fallas de IDOR, ataques de introspección, DoS y…
⤷ Title: When Insiders Become the Greatest Threat — The Intel Case and a Hidden Corporate Crisis
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:33:32 GMT
════════════════════════
⌗ Tags: #cybercrime #hacking #data_breach #inside_job #cybersecurity
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:33:32 GMT
════════════════════════
⌗ Tags: #cybercrime #hacking #data_breach #inside_job #cybersecurity
Medium
When Insiders Become the Greatest Threat — The Intel Case and a Hidden Corporate Crisis
The notification came on July 7, 2024. Jinfeng Luo, a software engineer who had spent over a decade developing electronic design…
⤷ Title: HackTheBox Forest (AD series)
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:15:32 GMT
════════════════════════
⌗ Tags: #hackthebox #hacking
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:15:32 GMT
════════════════════════
⌗ Tags: #hackthebox #hacking
Medium
HackTheBox Forest (AD series)
Nmap gives us a basic lay of the land
⤷ Title: Tuesday Morning Threat Report: Nov 11, 2025
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:57:47 GMT
════════════════════════
⌗ Tags: #jlr_ransomwar #ai_security #cybersecurity
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:57:47 GMT
════════════════════════
⌗ Tags: #jlr_ransomwar #ai_security #cybersecurity
Medium
Tuesday Morning Threat Report: Nov 11, 2025
A cyberattack reduces the U.K.’s GDP and Google finds malware using AI to self-modify