⤷ Title: Critical Devolutions Server Flaw (CVE-2025-12485, CVSS 9.4) Allows User Impersonation via Pre-MFA Cookie Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:29:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Credential Management #Critical Vulnerability #CVE_2025_12485 #Devolutions Server #PAM #privilege escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:29:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Credential Management #Critical Vulnerability #CVE_2025_12485 #Devolutions Server #PAM #privilege escalation
Daily CyberSecurity
Critical Devolutions Server Flaw (CVE-2025-12485, CVSS 9.4) Allows User Impersonation via Pre-MFA Cookie Hijacking
Devolutions patched two flaws in Devolutions Server: A Critical (CVSS 9.4) Auth Bypass allows user impersonation via pre-MFA cookie replay, and another flaw leaks plaintext passwords to view-only users.
⤷ Title: Critical WatchGuard Firebox Flaw (CVE-2025-59396, CVSS 9.8) Allows Unauthenticated Admin SSH Takeover via Default Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:25:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59396 #default credentials #Firebox #misconfiguration #network_security #ssh #WatchGuard
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:25:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_59396 #default credentials #Firebox #misconfiguration #network_security #ssh #WatchGuard
Daily CyberSecurity
Critical WatchGuard Firebox Flaw (CVE-2025-59396, CVSS 9.8) Allows Unauthenticated Admin SSH Takeover via Default Credentials
A Critical (CVSS 9.8) flaw (CVE-2025-59396) in WatchGuard Firebox allows unauthenticated remote root access via SSH on port 4118 using default credentials (admin:readwrite). Patch immediately.
⤷ Title: Critical GE Vernova ICS Flaw (CVE-2025-3222, CVSS 9.3) Allows Authentication Bypass in Smallworld Master File Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:22:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_3222 #GE Vernova #ICS #OT Security #Smallworld
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:22:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_3222 #GE Vernova #ICS #OT Security #Smallworld
Daily CyberSecurity
Critical GE Vernova ICS Flaw (CVE-2025-3222, CVSS 9.3) Allows Authentication Bypass in Smallworld Master File Server
GE Vernova patched a Critical Auth Bypass flaw (CVE-2025-3222) in Smallworld Master File Server. The flaw could allow users with system knowledge to circumvent authentication. Update immediately.
⤷ Title: North Korea’s KONNI APT Hijacks Google Find Hub to Remotely Wipe and Track South Korean Android Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:16:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Find Hub Abuse #Google Account #KakaoTalk #KONNI APT #North Korea #Remote Wipe #social engineering #south korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:16:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Find Hub Abuse #Google Account #KakaoTalk #KONNI APT #North Korea #Remote Wipe #social engineering #south korea
Daily CyberSecurity
North Korea's KONNI APT Hijacks Google Find Hub to Remotely Wipe and Track South Korean Android Devices
North Korea's KONNI APT is exploiting stolen Google accounts and the Find Hub service to remotely wipe South Korean Android devices for data destruction and surveillance, then spreading malware via KakaoTalk.
⤷ Title: Critical Calibre Flaw (CVE-2025-64486, CVSS 9.3) Allows RCE via Malicious FB2 E-book
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Calibre #CVE_2025_64486 #E_book Manager #FB2 #FictionBook #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Calibre #CVE_2025_64486 #E_book Manager #FB2 #FictionBook #rce
Daily CyberSecurity
Critical Calibre Flaw (CVE-2025-64486, CVSS 9.3) Allows RCE via Malicious FB2 E-book
A Critical (CVSS 9.3) RCE flaw (CVE-2025-64486) in Calibre allows arbitrary code execution when a user views or converts a malicious FB2 e-book due to unsafe filename handling. Update to v8.14.0.
⤷ Title: Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
Daily CyberSecurity
Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
ENKI exposed a Lazarus Group espionage campaign targeting aerospace/defense firms. The new Comebacker variant uses malicious Word macros and ChaCha20/AES to deliver a memory-resident backdoor.
⤷ Title: DragonForce Ransomware Evolves with BYOVD to Kill EDR and Fixes Encryption Flaws in Conti V3 Codebase
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:00:29 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Conti V3 #cybersecurity #DragonForce #EDR Bypass #MinGW #RaaS #vulnerable driver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:00:29 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Conti V3 #cybersecurity #DragonForce #EDR Bypass #MinGW #RaaS #vulnerable driver
Daily CyberSecurity
DragonForce Ransomware Evolves with BYOVD to Kill EDR and Fixes Encryption Flaws in Conti V3 Codebase
The Acronis Threat Research Unit (TRU) has identified a new DragonForce ransomware variant that showcases a dramatic evolution in both technical sophistication and organizational structure. The up…
⤷ Title: Vulnerabilidades en GraphQL API: Guía de Explotación, Descubrimiento y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #bug_bounty #technology #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #bug_bounty #technology #hacking
Medium
Vulnerabilidades en GraphQL API: Guía de Explotación, Descubrimiento y Mitigación
Guía completa sobre vulnerabilidades en APIs GraphQL: descubrimiento de endpoints, fallas de IDOR, ataques de introspección, DoS y…
⤷ Title: When Insiders Become the Greatest Threat — The Intel Case and a Hidden Corporate Crisis
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:33:32 GMT
════════════════════════
⌗ Tags: #cybercrime #hacking #data_breach #inside_job #cybersecurity
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:33:32 GMT
════════════════════════
⌗ Tags: #cybercrime #hacking #data_breach #inside_job #cybersecurity
Medium
When Insiders Become the Greatest Threat — The Intel Case and a Hidden Corporate Crisis
The notification came on July 7, 2024. Jinfeng Luo, a software engineer who had spent over a decade developing electronic design…
⤷ Title: HackTheBox Forest (AD series)
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:15:32 GMT
════════════════════════
⌗ Tags: #hackthebox #hacking
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:15:32 GMT
════════════════════════
⌗ Tags: #hackthebox #hacking
Medium
HackTheBox Forest (AD series)
Nmap gives us a basic lay of the land
⤷ Title: Tuesday Morning Threat Report: Nov 11, 2025
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:57:47 GMT
════════════════════════
⌗ Tags: #jlr_ransomwar #ai_security #cybersecurity
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:57:47 GMT
════════════════════════
⌗ Tags: #jlr_ransomwar #ai_security #cybersecurity
Medium
Tuesday Morning Threat Report: Nov 11, 2025
A cyberattack reduces the U.K.’s GDP and Google finds malware using AI to self-modify
⤷ Title: Rust PE RE Challenge
════════════════════════
𐀪 Author: Farhann Mahmoodi
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:48:35 GMT
════════════════════════
⌗ Tags: #computer_science #information_technology #reverse_engineering #programming #cybersecurity
════════════════════════
𐀪 Author: Farhann Mahmoodi
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:48:35 GMT
════════════════════════
⌗ Tags: #computer_science #information_technology #reverse_engineering #programming #cybersecurity
Medium
Rust PE RE Challenge
Here’s another reverse engineering challenge from this year’s Huntress CTF.
⤷ Title: Windows Recall: The VBS Enclave Paradox and the Evolution of Endpoint Espionage
════════════════════════
𐀪 Author: Berend Watchus
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:40:38 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #cybercrime #windows #information_security
════════════════════════
𐀪 Author: Berend Watchus
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:40:38 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #cybercrime #windows #information_security
Medium
Windows Recall: The VBS Enclave Paradox and the Evolution of Endpoint Espionage
Author: Berend Watchus November 11, 2025 Blog article
⤷ Title: Common Cybersecurity Myths You Should Stop Believing
════════════════════════
𐀪 Author: Ferdi Edogawa
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:18:28 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #cyber_security_awareness #cyberattack
════════════════════════
𐀪 Author: Ferdi Edogawa
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:18:28 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #cyber_security_awareness #cyberattack
Medium
Common Cybersecurity Myths You Should Stop Believing
In today’s digital world, cybersecurity isn’t just a concern for IT professionals — it’s a shared responsibility for everyone who uses…
⤷ Title: Free, but Not Innocent: Anatomy of the Legal Fraud Dominating Online Commerce
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:06:47 GMT
════════════════════════
⌗ Tags: #commerce #legal #cybersecurity #online_business #fraud
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:06:47 GMT
════════════════════════
⌗ Tags: #commerce #legal #cybersecurity #online_business #fraud
Medium
Free, but Not Innocent: Anatomy of the Legal Fraud Dominating Online Commerce
The Mirage of “Free”
⤷ Title: Cyberdefenders PacketMaze Lab Solution
════════════════════════
𐀪 Author: Muhammad Afif Faizun
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:51:49 GMT
════════════════════════
⌗ Tags: #cyberdefender #ctf_writeup #cyberdefenders_writeup #cybersecurity
════════════════════════
𐀪 Author: Muhammad Afif Faizun
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:51:49 GMT
════════════════════════
⌗ Tags: #cyberdefender #ctf_writeup #cyberdefenders_writeup #cybersecurity
Medium
Cyberdefenders PacketMaze Lab Solution
https://cyberdefenders.org/blueteam-ctf-challenges/achievements/zque/packetmaze/
⤷ Title: Splunk Detection Lab: APT Taeddonggong Simulation (Splunk Boss of the SOC)
════════════════════════
𐀪 Author: Julian Smith
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:46:31 GMT
════════════════════════
⌗ Tags: #blue_team #incident_response #cybersecurity
════════════════════════
𐀪 Author: Julian Smith
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:46:31 GMT
════════════════════════
⌗ Tags: #blue_team #incident_response #cybersecurity
Medium
🎯 Splunk Detection Lab: APT Taeddonggong Simulation (Splunk Boss of the SOC)
1️⃣ Scenario Overview
⤷ Title: Adli Bilişim Açısından CD/DVD Analizi
════════════════════════
𐀪 Author: Ayça Aslan
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:34:02 GMT
════════════════════════
⌗ Tags: #cybercrime #dfir_software #dfir #ftk_imager #cybersecurity
════════════════════════
𐀪 Author: Ayça Aslan
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:34:02 GMT
════════════════════════
⌗ Tags: #cybercrime #dfir_software #dfir #ftk_imager #cybersecurity
Medium
Adli Bilişim Açısından CD/DVD Analizi
Philips şirketince 1974 yılında geliştirilmiş olan CD’ler, Ses sinyallerini sayısal ve optik birimlerce okunabilecek biçimde küçük bir disk…
⤷ Title: Would you still trust ChatGPT with sensitive data after knowing this?
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:48 GMT
════════════════════════
⌗ Tags: #information_security #chatgpt #ai #cybersecurity #mcp_server
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:48 GMT
════════════════════════
⌗ Tags: #information_security #chatgpt #ai #cybersecurity #mcp_server
Medium
Would you still trust ChatGPT with sensitive data after knowing this?
We trust ChatGPT with everything — from personal brainstorming to professional secrets. But what if someone could trick it into spilling…
⤷ Title: SigmaOptimizer: End-to-End LLM Tool for Automated Sigma Rule Generation and Testing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:15:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #DetectionEngineering #LLM #PowerShell #SigmaOptimizer #SigmaRules #ThreatHunting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:15:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #DetectionEngineering #LLM #PowerShell #SigmaOptimizer #SigmaRules #ThreatHunting
Penetration Testing Tools
SigmaOptimizer: End-to-End LLM Tool for Automated Sigma Rule Generation and Testing
SigmaOptimizer is an E2E PowerShell tool that uses LLMs to automatically create, test, and optimize Sigma rules based on real-world security logs.
⤷ Title: APT-C-60 Returns: New SpyGlace Malware Hides in Fake Résumé VHDX Attachments
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
Penetration Testing Tools
APT-C-60 Returns: New SpyGlace Malware Hides in Fake Résumé VHDX Attachments
APT-C-60 targets HR staff with fake resumes attached as VHDX files. The new SpyGlace malware variants use Git, COM hijacking, and GitHub for control.