⤷ Title: Critical GE Vernova ICS Flaw (CVE-2025-3222, CVSS 9.3) Allows Authentication Bypass in Smallworld Master File Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:22:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_3222 #GE Vernova #ICS #OT Security #Smallworld
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:22:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_3222 #GE Vernova #ICS #OT Security #Smallworld
Daily CyberSecurity
Critical GE Vernova ICS Flaw (CVE-2025-3222, CVSS 9.3) Allows Authentication Bypass in Smallworld Master File Server
GE Vernova patched a Critical Auth Bypass flaw (CVE-2025-3222) in Smallworld Master File Server. The flaw could allow users with system knowledge to circumvent authentication. Update immediately.
⤷ Title: North Korea’s KONNI APT Hijacks Google Find Hub to Remotely Wipe and Track South Korean Android Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:16:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Find Hub Abuse #Google Account #KakaoTalk #KONNI APT #North Korea #Remote Wipe #social engineering #south korea
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:16:08 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Find Hub Abuse #Google Account #KakaoTalk #KONNI APT #North Korea #Remote Wipe #social engineering #south korea
Daily CyberSecurity
North Korea's KONNI APT Hijacks Google Find Hub to Remotely Wipe and Track South Korean Android Devices
North Korea's KONNI APT is exploiting stolen Google accounts and the Find Hub service to remotely wipe South Korean Android devices for data destruction and surveillance, then spreading malware via KakaoTalk.
⤷ Title: Critical Calibre Flaw (CVE-2025-64486, CVSS 9.3) Allows RCE via Malicious FB2 E-book
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Calibre #CVE_2025_64486 #E_book Manager #FB2 #FictionBook #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Calibre #CVE_2025_64486 #E_book Manager #FB2 #FictionBook #rce
Daily CyberSecurity
Critical Calibre Flaw (CVE-2025-64486, CVSS 9.3) Allows RCE via Malicious FB2 E-book
A Critical (CVSS 9.3) RCE flaw (CVE-2025-64486) in Calibre allows arbitrary code execution when a user views or converts a malicious FB2 e-book due to unsafe filename handling. Update to v8.14.0.
⤷ Title: Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #aerospace #APT #ChaCha20 #Comebacker #cyber_espionage #defense #Lazarus Group #Macro Malware
Daily CyberSecurity
Lazarus Group Attacks Aerospace/Defense with New ChaCha20-Encrypted Comebacker Backdoor
ENKI exposed a Lazarus Group espionage campaign targeting aerospace/defense firms. The new Comebacker variant uses malicious Word macros and ChaCha20/AES to deliver a memory-resident backdoor.
⤷ Title: DragonForce Ransomware Evolves with BYOVD to Kill EDR and Fixes Encryption Flaws in Conti V3 Codebase
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:00:29 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Conti V3 #cybersecurity #DragonForce #EDR Bypass #MinGW #RaaS #vulnerable driver
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:00:29 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Conti V3 #cybersecurity #DragonForce #EDR Bypass #MinGW #RaaS #vulnerable driver
Daily CyberSecurity
DragonForce Ransomware Evolves with BYOVD to Kill EDR and Fixes Encryption Flaws in Conti V3 Codebase
The Acronis Threat Research Unit (TRU) has identified a new DragonForce ransomware variant that showcases a dramatic evolution in both technical sophistication and organizational structure. The up…
⤷ Title: Vulnerabilidades en GraphQL API: Guía de Explotación, Descubrimiento y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #bug_bounty #technology #hacking
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_development #bug_bounty #technology #hacking
Medium
Vulnerabilidades en GraphQL API: Guía de Explotación, Descubrimiento y Mitigación
Guía completa sobre vulnerabilidades en APIs GraphQL: descubrimiento de endpoints, fallas de IDOR, ataques de introspección, DoS y…
⤷ Title: When Insiders Become the Greatest Threat — The Intel Case and a Hidden Corporate Crisis
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:33:32 GMT
════════════════════════
⌗ Tags: #cybercrime #hacking #data_breach #inside_job #cybersecurity
════════════════════════
𐀪 Author: David SEHYEON Baek
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:33:32 GMT
════════════════════════
⌗ Tags: #cybercrime #hacking #data_breach #inside_job #cybersecurity
Medium
When Insiders Become the Greatest Threat — The Intel Case and a Hidden Corporate Crisis
The notification came on July 7, 2024. Jinfeng Luo, a software engineer who had spent over a decade developing electronic design…
⤷ Title: HackTheBox Forest (AD series)
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:15:32 GMT
════════════════════════
⌗ Tags: #hackthebox #hacking
════════════════════════
𐀪 Author: SilentExploit
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:15:32 GMT
════════════════════════
⌗ Tags: #hackthebox #hacking
Medium
HackTheBox Forest (AD series)
Nmap gives us a basic lay of the land
⤷ Title: Tuesday Morning Threat Report: Nov 11, 2025
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:57:47 GMT
════════════════════════
⌗ Tags: #jlr_ransomwar #ai_security #cybersecurity
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:57:47 GMT
════════════════════════
⌗ Tags: #jlr_ransomwar #ai_security #cybersecurity
Medium
Tuesday Morning Threat Report: Nov 11, 2025
A cyberattack reduces the U.K.’s GDP and Google finds malware using AI to self-modify
⤷ Title: Rust PE RE Challenge
════════════════════════
𐀪 Author: Farhann Mahmoodi
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:48:35 GMT
════════════════════════
⌗ Tags: #computer_science #information_technology #reverse_engineering #programming #cybersecurity
════════════════════════
𐀪 Author: Farhann Mahmoodi
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:48:35 GMT
════════════════════════
⌗ Tags: #computer_science #information_technology #reverse_engineering #programming #cybersecurity
Medium
Rust PE RE Challenge
Here’s another reverse engineering challenge from this year’s Huntress CTF.
⤷ Title: Windows Recall: The VBS Enclave Paradox and the Evolution of Endpoint Espionage
════════════════════════
𐀪 Author: Berend Watchus
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:40:38 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #cybercrime #windows #information_security
════════════════════════
𐀪 Author: Berend Watchus
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:40:38 GMT
════════════════════════
⌗ Tags: #cyber_security_awareness #cybersecurity #cybercrime #windows #information_security
Medium
Windows Recall: The VBS Enclave Paradox and the Evolution of Endpoint Espionage
Author: Berend Watchus November 11, 2025 Blog article
⤷ Title: Common Cybersecurity Myths You Should Stop Believing
════════════════════════
𐀪 Author: Ferdi Edogawa
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:18:28 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #cyber_security_awareness #cyberattack
════════════════════════
𐀪 Author: Ferdi Edogawa
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:18:28 GMT
════════════════════════
⌗ Tags: #cybercrime #cybersecurity #cyber_security_awareness #cyberattack
Medium
Common Cybersecurity Myths You Should Stop Believing
In today’s digital world, cybersecurity isn’t just a concern for IT professionals — it’s a shared responsibility for everyone who uses…
⤷ Title: Free, but Not Innocent: Anatomy of the Legal Fraud Dominating Online Commerce
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:06:47 GMT
════════════════════════
⌗ Tags: #commerce #legal #cybersecurity #online_business #fraud
════════════════════════
𐀪 Author: Rodrigo Gutierrez
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 01:06:47 GMT
════════════════════════
⌗ Tags: #commerce #legal #cybersecurity #online_business #fraud
Medium
Free, but Not Innocent: Anatomy of the Legal Fraud Dominating Online Commerce
The Mirage of “Free”
⤷ Title: Cyberdefenders PacketMaze Lab Solution
════════════════════════
𐀪 Author: Muhammad Afif Faizun
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:51:49 GMT
════════════════════════
⌗ Tags: #cyberdefender #ctf_writeup #cyberdefenders_writeup #cybersecurity
════════════════════════
𐀪 Author: Muhammad Afif Faizun
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:51:49 GMT
════════════════════════
⌗ Tags: #cyberdefender #ctf_writeup #cyberdefenders_writeup #cybersecurity
Medium
Cyberdefenders PacketMaze Lab Solution
https://cyberdefenders.org/blueteam-ctf-challenges/achievements/zque/packetmaze/
⤷ Title: Splunk Detection Lab: APT Taeddonggong Simulation (Splunk Boss of the SOC)
════════════════════════
𐀪 Author: Julian Smith
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:46:31 GMT
════════════════════════
⌗ Tags: #blue_team #incident_response #cybersecurity
════════════════════════
𐀪 Author: Julian Smith
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:46:31 GMT
════════════════════════
⌗ Tags: #blue_team #incident_response #cybersecurity
Medium
🎯 Splunk Detection Lab: APT Taeddonggong Simulation (Splunk Boss of the SOC)
1️⃣ Scenario Overview
⤷ Title: Adli Bilişim Açısından CD/DVD Analizi
════════════════════════
𐀪 Author: Ayça Aslan
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:34:02 GMT
════════════════════════
⌗ Tags: #cybercrime #dfir_software #dfir #ftk_imager #cybersecurity
════════════════════════
𐀪 Author: Ayça Aslan
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:34:02 GMT
════════════════════════
⌗ Tags: #cybercrime #dfir_software #dfir #ftk_imager #cybersecurity
Medium
Adli Bilişim Açısından CD/DVD Analizi
Philips şirketince 1974 yılında geliştirilmiş olan CD’ler, Ses sinyallerini sayısal ve optik birimlerce okunabilecek biçimde küçük bir disk…
⤷ Title: Would you still trust ChatGPT with sensitive data after knowing this?
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:48 GMT
════════════════════════
⌗ Tags: #information_security #chatgpt #ai #cybersecurity #mcp_server
════════════════════════
𐀪 Author: Cyber-AppSec
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 00:02:48 GMT
════════════════════════
⌗ Tags: #information_security #chatgpt #ai #cybersecurity #mcp_server
Medium
Would you still trust ChatGPT with sensitive data after knowing this?
We trust ChatGPT with everything — from personal brainstorming to professional secrets. But what if someone could trick it into spilling…
⤷ Title: SigmaOptimizer: End-to-End LLM Tool for Automated Sigma Rule Generation and Testing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:15:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #DetectionEngineering #LLM #PowerShell #SigmaOptimizer #SigmaRules #ThreatHunting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:15:46 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity #DetectionEngineering #LLM #PowerShell #SigmaOptimizer #SigmaRules #ThreatHunting
Penetration Testing Tools
SigmaOptimizer: End-to-End LLM Tool for Automated Sigma Rule Generation and Testing
SigmaOptimizer is an E2E PowerShell tool that uses LLMs to automatically create, test, and optimize Sigma rules based on real-world security logs.
⤷ Title: APT-C-60 Returns: New SpyGlace Malware Hides in Fake Résumé VHDX Attachments
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:09:06 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT_C_60 #Cyberespionage #GitHubAbuse #HRPersonnel #JPCERT #phishing #SpyGlace #VHDX
Penetration Testing Tools
APT-C-60 Returns: New SpyGlace Malware Hides in Fake Résumé VHDX Attachments
APT-C-60 targets HR staff with fake resumes attached as VHDX files. The new SpyGlace malware variants use Git, COM hijacking, and GitHub for control.
⤷ Title: Rust Coreutils 0.4.0 Released: 85.8% GNU Compatibility & Major Performance Boosts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:06:58 +0000
════════════════════════
⌗ Tags: #Technology #Coreutils040 #GNUCoreutils #OpenSource #programming #Rust #RustCoreutils #SystemUtilities #uutils
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:06:58 +0000
════════════════════════
⌗ Tags: #Technology #Coreutils040 #GNUCoreutils #OpenSource #programming #Rust #RustCoreutils #SystemUtilities #uutils
Penetration Testing Tools
Rust Coreutils 0.4.0 Released: 85.8% GNU Compatibility & Major Performance Boosts
Rust Coreutils 0.4.0 is out, passing 85.8% of GNU tests. It brings major speed boosts to factor and tsort and improves cross-platform stability.
⤷ Title: RondoDox Botnet V2 Escalates: 75+ Exploits Target IoT and Enterprise Systems
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:05:30 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #DDoS #EnterpriseSecurity #Exploits #IoT #Mirai #RondoDoxV2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 11 Nov 2025 03:05:30 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #cybersecurity #DDoS #EnterpriseSecurity #Exploits #IoT #Mirai #RondoDoxV2
Penetration Testing Tools
RondoDox Botnet V2 Escalates: 75+ Exploits Target IoT and Enterprise Systems
RondoDox v2 botnet is live, using over 75 exploits to target IoT and enterprise apps. It features XOR obfuscation and multi-stage infection for massive DDoS power.