⤷ Title: Open WebUI XSS Flaw (CVE-2025-64495) Risks Admin RCE via Malicious Prompts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:15:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Interface #CVE_2025_64495 #Open WebUI #Prompt injection #rce #Stored XSS #Svelte #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:15:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Interface #CVE_2025_64495 #Open WebUI #Prompt injection #rce #Stored XSS #Svelte #XSS
Daily CyberSecurity
Open WebUI XSS Flaw (CVE-2025-64495) Risks Admin RCE via Malicious Prompts
A XSS flaw in Open WebUI allows authenticated users to achieve Admin RCE by injecting JavaScript into rich text prompts, then exploiting the Functions feature. Update to v0.6.35.
⤷ Title: Legacy Malware Resurfaces: DarkComet RAT Uses Bitcoin Wallet Lure to Deploy UPX-Packed Payload
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:10:56 +0000
════════════════════════
⌗ Tags: #Malware #Bitcoin Lure #DarkComet #Keylogging #Legacy Malware #persistence #rat #Remote Access Trojan #UPX Packer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:10:56 +0000
════════════════════════
⌗ Tags: #Malware #Bitcoin Lure #DarkComet #Keylogging #Legacy Malware #persistence #rat #Remote Access Trojan #UPX Packer
Daily CyberSecurity
Legacy Malware Resurfaces: DarkComet RAT Uses Bitcoin Wallet Lure to Deploy UPX-Packed Payload
A new campaign is using Bitcoin wallet lures to distribute DarkComet RAT. The UPX-packed trojan gains persistence via a fake explorer.exe binary and uses keylogging and remote control to steal data.
⤷ Title: CERT/CC Warns of Code Execution Flaws in Lite XL Text Editor (CVE-2025-12120, CVE-2025-12121)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:05:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.lite_project.lua #Arbitrary Code Execution #CVE_2025_12120 #Lite XL #Lua #rce #Supply Chain #text editor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:05:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.lite_project.lua #Arbitrary Code Execution #CVE_2025_12120 #Lite XL #Lua #rce #Supply Chain #text editor
Daily CyberSecurity
CERT/CC Warns of Code Execution Flaws in Lite XL Text Editor (CVE-2025-12120, CVE-2025-12121)
A Critical flaw in Lite XL (CVE-2025-12120) allows RCE when opening a project: the editor automatically executes malicious .lite_project.lua files, risking developer compromise.
⤷ Title: Moving to a new laptop is a pain
════════════════════════
𐀪 Author: Bruce Coulter
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:40:43 GMT
════════════════════════
⌗ Tags: #computers #internet #writing #hacking #technology
════════════════════════
𐀪 Author: Bruce Coulter
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:40:43 GMT
════════════════════════
⌗ Tags: #computers #internet #writing #hacking #technology
Medium
Moving to a new laptop is a pain
But damned if I’m going to pay to migrate apps and more
⤷ Title: Exploring AI Red Teaming: Challenges and Opportunities
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:35 GMT
════════════════════════
⌗ Tags: #ai_tools #ai #ai_red_teaming #hacking #cybersecurity
════════════════════════
𐀪 Author: Mainekhacker
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:35 GMT
════════════════════════
⌗ Tags: #ai_tools #ai #ai_red_teaming #hacking #cybersecurity
Medium
Exploring AI Red Teaming: Challenges and Opportunities
AI Red Teaming is an evolving field focused on evaluating AI systems’ security by simulating attacks and identifying vulnerabilities.
⤷ Title: Why 99% of Bug Hunters Fail — and How to Be the 1%
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:30 GMT
════════════════════════
⌗ Tags: #tech #ai #hacking #cybersecurity #programming
════════════════════════
𐀪 Author: Vipul Sonule
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:30 GMT
════════════════════════
⌗ Tags: #tech #ai #hacking #cybersecurity #programming
Medium
💥 Why 99% of Bug Hunters Fail — and How to Be the 1% 🧠💰
Hey there, hacker 👋 — Vipul here from The Hacker’s Log. Let’s be honest: bug hunting looks glamorous on Twitter, right? Everyone posting
⤷ Title: Detecting Attacker Behavior with Splunk: The Analytics Approach
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:32:29 GMT
════════════════════════
⌗ Tags: #women_in_tech #cybersecurity #hackthebox #information_security #infosec
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:32:29 GMT
════════════════════════
⌗ Tags: #women_in_tech #cybersecurity #hackthebox #information_security #infosec
Medium
Detecting Attacker Behavior with Splunk: The Analytics Approach
TTP-based detection catches known attacks. But what about zero-days and custom techniques? Statistical analysis and anomaly detection…
⤷ Title: All About MSF | Metasploit Framework Explained for Beginners
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:25 GMT
════════════════════════
⌗ Tags: #beginners_guide #learn_by_doing #cybersecurity #ethical_hacking #metasploit
════════════════════════
𐀪 Author: Shahzaib
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:25 GMT
════════════════════════
⌗ Tags: #beginners_guide #learn_by_doing #cybersecurity #ethical_hacking #metasploit
Medium
All About MSF | Metasploit Framework Explained for Beginners
My First Panic Attack with the Hacker’s Toolbox (And What I Learned)
⤷ Title: A Guide to Protecting Your Family from Online Threats
════════════════════════
𐀪 Author: Samina Perveen
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:18 GMT
════════════════════════
⌗ Tags: #online_safety #digital_parenting #cybersecurity_families #cybersecurity #osint_team
════════════════════════
𐀪 Author: Samina Perveen
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:39:18 GMT
════════════════════════
⌗ Tags: #online_safety #digital_parenting #cybersecurity_families #cybersecurity #osint_team
Medium
A Guide to Protecting Your Family from Online Threats
The Day My Eight-Year-Old Taught Me About Digital Safety
⤷ Title: Google Just Sued a Billion Dollar Organization That Has Been Defrauding Millions of People
════════════════════════
𐀪 Author: Tyson Martin
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:36:54 GMT
════════════════════════
⌗ Tags: #protection #cybersecurity #business_strategy #fraud #risk_management
════════════════════════
𐀪 Author: Tyson Martin
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:36:54 GMT
════════════════════════
⌗ Tags: #protection #cybersecurity #business_strategy #fraud #risk_management
Medium
Google Just Sued a Billion Dollar Organization That Has Been Defrauding Millions of People
TL;DR: Google filed the first-ever lawsuit against a phishing-as-a-service operation called Lighthouse. The China-based syndicate stole $1…
⤷ Title: How Proxy Websites Unlock the Internet: Privacy, Access, and Freedom Online
════════════════════════
𐀪 Author: Novada
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:28:30 GMT
════════════════════════
⌗ Tags: #online_privacy #proxy #digital_security #internet_freedom #cybersecurity
════════════════════════
𐀪 Author: Novada
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 01:28:30 GMT
════════════════════════
⌗ Tags: #online_privacy #proxy #digital_security #internet_freedom #cybersecurity
Medium
How Proxy Websites Unlock the Internet: Privacy, Access, and Freedom Online
The internet isn’t always open. Whether it’s a country-level block, a school firewall, or a regional content restriction, access can be…
⤷ Title: UniFi OS Security Warning: A flaw in the Backup API could let attackers run code without…
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:51:09 GMT
════════════════════════
⌗ Tags: #api #security_warning #threat_intelligence #cybersecurity #unifi
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:51:09 GMT
════════════════════════
⌗ Tags: #api #security_warning #threat_intelligence #cybersecurity #unifi
Medium
UniFi OS Security Warning: A flaw in the Backup API could let attackers run code without…
In early November 2025, researchers disclosed a severe unauthenticated remote code execution vulnerability in Ubiquiti’s UniFi OS…
⤷ Title: Developing a Robust Cybersecurity Incident Response Plan: A Step-by-Step Guide
════════════════════════
𐀪 Author: Steven Chin
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:37:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #incident_response_plan
════════════════════════
𐀪 Author: Steven Chin
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 00:37:51 GMT
════════════════════════
⌗ Tags: #cybersecurity #incident_response_plan
Medium
Developing a Robust Cybersecurity Incident Response Plan: A Step-by-Step Guide
Introduction
⤷ Title: No More Separate Passkeys: Windows 11 Adds API for Password Manager Integration
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:59:30 +0000
════════════════════════
⌗ Tags: #Windows #1Password #authentication #Bitwarden #fido #Passkeys #PasswordManager #Windows11 #WindowsHello
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:59:30 +0000
════════════════════════
⌗ Tags: #Windows #1Password #authentication #Bitwarden #fido #Passkeys #PasswordManager #Windows11 #WindowsHello
Daily CyberSecurity
No More Separate Passkeys: Windows 11 Adds API for Password Manager Integration
Windows 11 now supports a new API allowing password managers (like 1Password, Bitwarden) to handle passkey authentication directly, simplifying cross-platform sign-in.
⤷ Title: Steam Frame VR Unveiled: Valve’s Standalone Headset Targets Quest with Snapdragon & Foveated Streaming
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:33:45 +0000
════════════════════════
⌗ Tags: #Technology #FoveatedStreaming #PCVR #Snapdragon8Gen3 #StandaloneVR #SteamFrame #SteamOS #Valve #VRHeadset
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:33:45 +0000
════════════════════════
⌗ Tags: #Technology #FoveatedStreaming #PCVR #Snapdragon8Gen3 #StandaloneVR #SteamFrame #SteamOS #Valve #VRHeadset
Daily CyberSecurity
Steam Frame VR Unveiled: Valve's Standalone Headset Targets Quest with Snapdragon & Foveated Streaming
Valve unveiled Steam Frame VR, a standalone headset with Snapdragon 8 Gen 3, SteamOS, and Foveated Streaming, set to launch in early 2026.
⤷ Title: KMS38 Activation is Broken: Microsoft Removes License Transfer Mechanism in Windows 11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:29:16 +0000
════════════════════════
⌗ Tags: #Technology #Activation #Build26040 #KMS #KMS38 #Licensing #Microsoft #TechNews #Windows11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:29:16 +0000
════════════════════════
⌗ Tags: #Technology #Activation #Build26040 #KMS #KMS38 #Licensing #Microsoft #TechNews #Windows11
Daily CyberSecurity
KMS38 Activation is Broken: Microsoft Removes License Transfer Mechanism in Windows 11
Microsoft changed the KMS activation mechanism in Windows 11 (Build 26040+), removing the license transfer that KMS38 exploited, effectively breaking the activation method.
⤷ Title: Seagate Exos 4U100 Unveiled: 3.2 PB Storage Density for AI and Edge Data Centers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:20:21 +0000
════════════════════════
⌗ Tags: #Technology #Datacenter #Exos4U100 #GenerativeAI #HAMR #JBOD #SC25 #Seagate #Storage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:20:21 +0000
════════════════════════
⌗ Tags: #Technology #Datacenter #Exos4U100 #GenerativeAI #HAMR #JBOD #SC25 #Seagate #Storage
Daily CyberSecurity
Seagate Exos 4U100 Unveiled: 3.2 PB Storage Density for AI and Edge Data Centers
Seagate's new Exos 4U100 JBOD system offers 3.2 PB of high-density storage in a single chassis for AI and edge data centers, featuring HAMR and 30% lower power use.
⤷ Title: Android Sideloading Crackdown: Google to Verify All Apps, But Promises Power-User Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:12:49 +0000
════════════════════════
⌗ Tags: #Android #android #AntiFraud #AppVerification #CodeSigning #google #PowerUsers #security #Sideloading
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:12:49 +0000
════════════════════════
⌗ Tags: #Android #android #AntiFraud #AppVerification #CodeSigning #google #PowerUsers #security #Sideloading
Daily CyberSecurity
Android Sideloading Crackdown: Google to Verify All Apps, But Promises Power-User Bypass
Google will soon require all sideloaded Android apps to pass verification and code signing to combat fraud. However, the company is developing an "advanced process" for power users to bypass this.
⤷ Title: PAN-OS Flaw (CVE-2025-4619) Allows Unauthenticated Firewall Reboot via Single Crafted Packet
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 02:49:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_4619 #Decrypt Policy #Denial of Service #dos #firewall #Palo Alto Networks #PAN_OS #URL Proxy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 02:49:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_4619 #Decrypt Policy #Denial of Service #dos #firewall #Palo Alto Networks #PAN_OS #URL Proxy
Daily CyberSecurity
PAN-OS Flaw (CVE-2025-4619) Allows Unauthenticated Firewall Reboot via Single Crafted Packet
Palo Alto patched a DoS flaw (CVE-2025-4619) in PAN-OS. An unauthenticated attacker can remotely reboot the firewall if URL proxy or decryption policies are enabled.
⤷ Title: High-Severity GitLab XSS Flaw (CVE-2025-11224) Risks Kubernetes Proxy Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 02:07:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_11224 #Duo Workflow #gitlab #Kubernetes Proxy #security patch #Stored XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 02:07:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_11224 #Duo Workflow #gitlab #Kubernetes Proxy #security patch #Stored XSS
Daily CyberSecurity
High-Severity GitLab XSS Flaw (CVE-2025-11224) Risks Kubernetes Proxy Session Hijacking
GitLab patched a High-severity Stored XSS flaw (CVE-2025-11224, CVSS 7.7) in the Kubernetes proxy feature. The bug allows authenticated users to hijack administrator sessions. Update to v18.5.2+.
⤷ Title: $4500 Local File Inclusion: The Tiny Parameter That Exposed an Entire Infrastructure
════════════════════════
𐀪 Author: Swapnil Ade
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:26:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #lfi_vulnerability #application_security #bug_bounty
════════════════════════
𐀪 Author: Swapnil Ade
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 03:26:16 GMT
════════════════════════
⌗ Tags: #cybersecurity #lfi_vulnerability #application_security #bug_bounty
Medium
$4500 Local File Inclusion: The Tiny Parameter That Exposed an Entire Infrastructure
Summary: