⤷ Title: AI vs. AI: Microsoft Blocks Phishing Attack Using LLM-Generated Obfuscated Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Enhanced Threat #Credential Phishing #cybersecurity #LLM #Microsoft Defender #Microsoft Security Copilot #Obfuscation #SVG
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Enhanced Threat #Credential Phishing #cybersecurity #LLM #Microsoft Defender #Microsoft Security Copilot #Obfuscation #SVG
Daily CyberSecurity
AI vs. AI: Microsoft Blocks Phishing Attack Using LLM-Generated Obfuscated Code
Microsoft blocked a credential phishing campaign that used AI to generate complex, verbose code in an SVG file to obfuscate its payload and evade defenses.
⤷ Title: Fake Ukraine Police Notices Spread New Amatera Stealer and PureMiner
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 09:44:53 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Amatera Stealer #Crypto #Cryptojacking #Cybersecurity #Phishing #Police #PureMiner #SVG #Ukraine
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 09:44:53 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Amatera Stealer #Crypto #Cryptojacking #Cybersecurity #Phishing #Police #PureMiner #SVG #Ukraine
Hackread
Fake Ukraine Police Notices Spread New Amatera Stealer and PureMiner
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Fake Ukraine Police Notices Spread New Amatera Stealer and PureMiner
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 14:25:14 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Amatera Stealer #Crypto #Cryptojacking #Cybersecurity #Phishing #Police #PureMiner #SVG #Ukraine
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 14:25:14 +0000
════════════════════════
⌗ Tags: #Security #Malware #Phishing Scam #Amatera Stealer #Crypto #Cryptojacking #Cybersecurity #Phishing #Police #PureMiner #SVG #Ukraine
Hackread
Fake Ukraine Police Notices Spread New Amatera Stealer and PureMiner
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: AI-Powered Phishing: Microsoft Uncovers First-of-its-Kind Attack Using Generative Code Obfuscation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 03:48:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Credential Theft #cybersecurity #Generative AI #Microsoft #Microsoft Defender #Obfuscation #phishing #SVG
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 03:48:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI #Credential Theft #cybersecurity #Generative AI #Microsoft #Microsoft Defender #Obfuscation #phishing #SVG
Penetration Testing Tools
AI-Powered Phishing: Microsoft Uncovers First-of-its-Kind Attack Using Generative Code Obfuscation
Microsoft reports an AI-powered phishing campaign that used AI to generate complex, obfuscated code within an SVG file, designed to steal corporate credentials.
⤷ Title: New Phishing Campaign Impersonates Ukrainian Police to Deliver Amatera Stealer and PureMiner
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 03:38:28 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Stealer #Cryptojacking #FortiGuard #Infostealer #malware #phishing #PureMiner #SVG #Ukraine
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 03:38:28 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Stealer #Cryptojacking #FortiGuard #Infostealer #malware #phishing #PureMiner #SVG #Ukraine
Penetration Testing Tools
New Phishing Campaign Impersonates Ukrainian Police to Deliver Amatera Stealer and PureMiner
A phishing campaign is impersonating Ukrainian police via malicious SVG files to deliver Amatera Stealer and PureMiner, a stealthy cryptominer, to victims.
⤷ Title: Microsoft Flags AI Phishing Attack Hiding in SVG Files
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 09:46:08 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #AI #Artificial Intelligence #Fraud #LLM #Microsoft #Phishing #Scam #SVG
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 09:46:08 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #AI #Artificial Intelligence #Fraud #LLM #Microsoft #Phishing #Scam #SVG
Hackread
Microsoft Flags AI Phishing Attack Hiding in SVG Files
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Microsoft Discontinues Embedded SVG Support in Outlook for Enhanced Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 01:57:02 +0000
════════════════════════
⌗ Tags: #Microsoft #email security #Inline Images #Microsoft Outlook #Outlook Web #security update #SVG #XSS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 06 Oct 2025 01:57:02 +0000
════════════════════════
⌗ Tags: #Microsoft #email security #Inline Images #Microsoft Outlook #Outlook Web #security update #SVG #XSS
Penetration Testing Tools
Microsoft Discontinues Embedded SVG Support in Outlook for Enhanced Security
Microsoft is discontinuing support for embedded SVG images in Outlook for the web and Windows to mitigate XSS and other security risks. The change is being gradually rolled out.
⤷ Title: Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:04:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_10729 #Denial of Service #Qt SVG #rce #SVG Parsing #use after free
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:04:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_10729 #Denial of Service #Qt SVG #rce #SVG Parsing #use after free
Daily CyberSecurity
Qt Fixes Dual Critical Vulnerabilities (CVE-2025-10728 & CVE-2025-10729) in SVG Module
The Qt Group patched two critical flaws in Qt SVG: a UAF bug (CVE-2025-10729) that risks RCE, and recursive pattern element (CVE-2025-10728) leading to stack overflow DoS.
⤷ Title: SVG Smuggling: Fake Colombian Judicial Lure Deploys AsyncRAT via Malicious HTA File
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:18:14 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #Colombia #HTA File #phishing #rat #Remote Access Trojan #Seqrite #SVG Smuggling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:18:14 +0000
════════════════════════
⌗ Tags: #Malware #AsyncRAT #Colombia #HTA File #phishing #rat #Remote Access Trojan #Seqrite #SVG Smuggling
Daily CyberSecurity
SVG Smuggling: Fake Colombian Judicial Lure Deploys AsyncRAT via Malicious HTA File
Seqrite discovered a campaign using SVG smuggling and a fake Colombian court lure to deploy AsyncRAT. The SVG executes JS to stage a malicious HTA file, evading detection.
⤷ Title: Tykit Phishing: SVG Malware Used to Steal Microsoft 365 Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 25 Oct 2025 06:44:29 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Microsoft 365 #PhaaS #phishing #SVG #Tykit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 25 Oct 2025 06:44:29 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Microsoft 365 #PhaaS #phishing #SVG #Tykit
Penetration Testing Tools
Tykit Phishing: SVG Malware Used to Steal Microsoft 365 Credentials
A surge in the Tykit phishing campaign is targeting M365 users, using malicious SVG files with XOR obfuscated JavaScript to steal credentials.
⤷ Title: High-Severity Angular Flaw (CVE-2025-66412) Allows Stored XSS via SVG and MathML Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #Critical Vulnerability #Cross_Site Scripting #CVE_2025_66412 #SVG Injection #Template Compiler #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 00:06:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #Critical Vulnerability #Cross_Site Scripting #CVE_2025_66412 #SVG Injection #Template Compiler #XSS
Daily CyberSecurity
High-Severity Angular Flaw (CVE-2025-66412) Allows Stored XSS via SVG and MathML Bypass
A High-severity XSS flaw (CVE-2025-66412, CVSS 8.5) in Angular allows attackers to bypass sanitization and execute scripts via vulnerable SVG/MathML attributes. Update to v21.0.2 immediately.
⤷ Title: Zero-JS Clickjacking: SVG Filters Exploit iFrames to Steal Cross-Origin Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:32:53 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chromium #clickjacking #Cross_Origin #feBlend #Firefox #iFrame #Lira Rebane #SVG Filter #web security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 03:32:53 +0000
════════════════════════
⌗ Tags: #Vulnerability #Chromium #clickjacking #Cross_Origin #feBlend #Firefox #iFrame #Lira Rebane #SVG Filter #web security
⤷ Title: Multi-Stage SVG: Analyzing a Colombian Court-Themed Malware Campaign with 0% AV Detection
════════════════════════
𐀪 Author: Pavol Kluka
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 11:34:50 GMT
════════════════════════
⌗ Tags: #incident_response #malicious #svg #infosec #analysis
════════════════════════
𐀪 Author: Pavol Kluka
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 11:34:50 GMT
════════════════════════
⌗ Tags: #incident_response #malicious #svg #infosec #analysis
Medium
Multi-Stage SVG: Analyzing a Colombian Court-Themed Malware Campaign with 0% AV Detection
01 | Introduction
⤷ Title: Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
Daily CyberSecurity
Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
Roundcube patches two High-severity flaws: an SVG-based XSS and a CSS sanitizer bypass. Protect your inbox—update to v1.6.12 or v1.5.12 now.
⤷ Title: Angular Security Alert: High-Severity SVG Flaw CVE-2026-22610 Exposes Apps to XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 01:59:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CVE_2026_22610 #Front_end Development #javascript #Patch Alert #SVG Vulnerability #Web Security #XSS (Cross_Site Scripting)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 01:59:12 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CVE_2026_22610 #Front_end Development #javascript #Patch Alert #SVG Vulnerability #Web Security #XSS (Cross_Site Scripting)
Daily CyberSecurity
Angular Security Alert: High-Severity SVG Flaw CVE-2026-22610 Exposes Apps to XSS
Angular CVE-2026-22610 (CVSS 8.5) allows XSS via SVG script attributes. Update to v21.0.7 or v20.3.16 immediately to secure your apps.
⤷ Title: Critical 9.3 CVSS Flaw in SiYuan Lets Hackers Steal Private Notes via SVG Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 00:28:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_29183 #cybersecurity #infosec #Patch Alert #Personal Knowledge Management #SiYuan #SVG Injection #Vulnerability #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Mar 2026 00:28:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CVE_2026_29183 #cybersecurity #infosec #Patch Alert #Personal Knowledge Management #SiYuan #SVG Injection #Vulnerability #XSS
Daily CyberSecurity
Critical 9.3 CVSS Flaw in SiYuan Lets Hackers Steal Private Notes via SVG Injection
A critical 9.3 CVSS reflected XSS flaw (CVE-2026-29183) in SiYuan's dynamic icon API lets attackers steal private notes via SVG injection. Update now.
⤷ Title: North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 07:15:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #developer targeting #DPRK #Elastic Security Labs #Infostealer #North Korea #OtterCookie #SVG steganography
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 07:15:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #developer targeting #DPRK #Elastic Security Labs #Infostealer #North Korea #OtterCookie #SVG steganography
Daily CyberSecurity
North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests
At a glance Actor / group DPRK-aligned group behind the Contagious Interview campaign (Elastic tracks it as REF9403) Activity type Social-engineering job lures delivering trojanized coding project…