⤷ Title: High-Severity Memos Flaw (CVE-2024-21635) Allows Hackers to Stay Logged In After Password Change
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:48:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Token #CVE_2024_21635 #Memos #Session Management #Token Invalidation #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:48:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Access Token #CVE_2024_21635 #Memos #Session Management #Token Invalidation #Vulnerability
Daily CyberSecurity
High-Severity Memos Flaw (CVE-2024-21635) Allows Hackers to Stay Logged In After Password Change
A High-severity flaw (CVE-2024-21635) in Memos fails to invalidate Access Tokens upon password change, allowing attackers to maintain access to the knowledge base. Update to v0.25.2.
⤷ Title: HelloKitty Successor Kraken Ransomware Hits Windows/ESXi, Benchmarks Victim Performance Before Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Benchmarking #Cloudflared #Cross_Platform #ESXi #HelloKitty #Kraken Ransomware #RaaS #SSHFS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Benchmarking #Cloudflared #Cross_Platform #ESXi #HelloKitty #Kraken Ransomware #RaaS #SSHFS
Daily CyberSecurity
HelloKitty Successor Kraken Ransomware Hits Windows/ESXi, Benchmarks Victim Performance Before Encryption
Cisco Talos reports Kraken, a HelloKitty successor, is a cross-platform RaaS targeting Windows/ESXi. The malware uniquely benchmarks CPU/IO to optimize encryption speed and uses Cloudflared/SSHFS for persistence.
⤷ Title: Critical IBM AIX RCE (CVE-2025-36250, CVSS 10.0) Flaw Exposes NIM Private Keys and Risks Directory Traversal
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:32:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #Directory Traversal #Enterprise Security #IBM AIX #NIM Private Key #rce #VIOS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:32:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #Directory Traversal #Enterprise Security #IBM AIX #NIM Private Key #rce #VIOS
Daily CyberSecurity
Critical IBM AIX RCE (CVE-2025-36250, CVSS 10.0) Flaw Exposes NIM Private Keys and Risks Directory Traversal
IBM patched four critical flaws in AIX/VIOS. The RCE (CVSS 10.0) in nimesis and CVE-2025-36096 allow remote attackers to execute commands and obtain NIM private keys. Update immediately.
⤷ Title: North Korea’s Contagious Interview APT Uses JSON Keeper and GitLab to Deliver BeaverTail Spyware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:30:41 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BeaverTail #Contagious Interview #DPRK #gitlab #InvisibleFerret #JSON Storage #Supply Chain #Web3
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:30:41 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BeaverTail #Contagious Interview #DPRK #gitlab #InvisibleFerret #JSON Storage #Supply Chain #Web3
Daily CyberSecurity
North Korea's Contagious Interview APT Uses JSON Keeper and GitLab to Deliver BeaverTail Spyware
NVISO exposed the Contagious Interview APT using JSON Keeper and npoint.io as covert C2 channels. The North Korean group uses fake job lures on GitLab to deploy BeaverTail to steal Web3 credentials.
⤷ Title: Record Supply Chain Attack: 150,000+ Malicious npm Packages Flooded Registry for Token Farming Rewards
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:25:32 +0000
════════════════════════
⌗ Tags: #Malware #Automated Abuse #AWS Inspector #npm #Registry Pollution #supply chain attack #tea.xyz #Token Farming
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:25:32 +0000
════════════════════════
⌗ Tags: #Malware #Automated Abuse #AWS Inspector #npm #Registry Pollution #supply chain attack #tea.xyz #Token Farming
Daily CyberSecurity
Record Supply Chain Attack: 150,000+ Malicious npm Packages Flooded Registry for Token Farming Rewards
AWS Inspector exposed the largest npm supply chain incident ever: 150,000+ malicious packages were uploaded in a coordinated campaign to exploit tea.xyz token rewards via tea.yaml files.
⤷ Title: CISA Warns: Critical Lynx+ Gateway Flaw (CVSS 10.0) Allows Unauthenticated Remote Reset; Vendor Non-Responsive
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Critical Vulnerability #CVSS 10.0 #GIC #ICS security #Lynx+ Gateway #Missing Authentication #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:20:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Critical Vulnerability #CVSS 10.0 #GIC #ICS security #Lynx+ Gateway #Missing Authentication #unauthenticated access
Daily CyberSecurity
CISA Warns: Critical Lynx+ Gateway Flaw (CVSS 10.0) Allows Unauthenticated Remote Reset; Vendor Non-Responsive
CISA warned of four flaws in Lynx+ Gateway. The Critical (CVSS 10.0) Auth Bypass allows unauthenticated remote reset and cleartext credential theft. Vendor GIC has not responded to CISA.
⤷ Title: Lumma Stealer Resurfaces After Doxxing with New Browser Fingerprinting to Target High-Value Victims
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:10:06 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #browser fingerprinting #doxxing #Infostealer #Lumma Stealer #Process injection #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:10:06 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #browser fingerprinting #doxxing #Infostealer #Lumma Stealer #Process injection #Trend Micro
Daily CyberSecurity
Lumma Stealer Resurfaces After Doxxing with New Browser Fingerprinting to Target High-Value Victims
Despite a recent doxxing attempt, Lumma Stealer has resurfaced, integrating browser fingerprinting into its C&C to collect WebGL/Canvas signatures for sandbox evasion and victim assessment.
⤷ Title: Phishing-as-a-Service Uncovered: Automated Kit Impersonates Aruba S.p.A. to Steal Credentials and Credit Cards
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:05:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aruba #Credential Theft #Credit card skimming #Multi_Stage Attack #PhaaS #phishing #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:05:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Aruba #Credential Theft #Credit card skimming #Multi_Stage Attack #PhaaS #phishing #Telegram C2
Daily CyberSecurity
Phishing-as-a-Service Uncovered: Automated Kit Impersonates Aruba S.p.A. to Steal Credentials and Credit Cards
A new report from Group-IB exposes a highly automated phishing framework engineered to impersonate Italian IT and web-services giant Aruba S.p.A., a company serving more than 5.4 million customers…
⤷ Title: New Yurei Ransomware Emerges: Go-Based Threat Uses ChaCha20-Poly1305 for Irreversible Double Extortion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Double Extortion #ECIES #Golang #Ransomware_as_a_Service #Yurei ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #ChaCha20 #Double Extortion #ECIES #Golang #Ransomware_as_a_Service #Yurei ransomware
Daily CyberSecurity
New Yurei Ransomware Emerges: Go-Based Threat Uses ChaCha20-Poly1305 for Irreversible Double Extortion
Security researchers at AhnLab have identified Yurei, a newly emerging ransomware group first observed in early September 2025. The group operates with a classic double-extortion model, infiltrati…
⤷ Title: How I Accidentally Discovered an Undocumented Behavior in “Web for Pentester 1”
════════════════════════
𐀪 Author: Zahi halimi
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:34:44 GMT
════════════════════════
⌗ Tags: #web_pentesting #pentesting #hacking
════════════════════════
𐀪 Author: Zahi halimi
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:34:44 GMT
════════════════════════
⌗ Tags: #web_pentesting #pentesting #hacking
Medium
How I Accidentally Discovered an Undocumented Behavior in “Web for Pentester 1”
Most security labs are built around predictable, well-documented vulnerabilities. But every once in a while, during experimentation, you…
⤷ Title: Write-up: Máquina “Expressway” de Hack The Box
════════════════════════
𐀪 Author: Marianoacostafc
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:18:35 GMT
════════════════════════
⌗ Tags: #writeup #hackthebox #cybersecurity #hacking
════════════════════════
𐀪 Author: Marianoacostafc
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 00:18:35 GMT
════════════════════════
⌗ Tags: #writeup #hackthebox #cybersecurity #hacking
Medium
Write-up: Máquina “Expressway” de Hack The Box
Vamos a hacer una nueva máquina, “Expressway”. Esta no tenía ninguna información, así que la cosa se ponía interesante desde el principio.
⤷ Title: Hide.me VPN review: A powerful toolkit for privacy experts in 2025
════════════════════════
𐀪 Author: Safelyo VPN
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:48:47 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #vpn #privacy #safelyo
════════════════════════
𐀪 Author: Safelyo VPN
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:48:47 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #vpn #privacy #safelyo
Medium
Hide.me VPN review: A powerful toolkit for privacy experts in 2025
This isn’t just another VPN. It’s a high-performance security toolkit for users who demand control.
⤷ Title: Skipping Cash, Going Mobile
════════════════════════
𐀪 Author: Decoded Intel
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:36:40 GMT
════════════════════════
⌗ Tags: #geopolitics #cybersecurity #africa #digital_payment #mauritania
════════════════════════
𐀪 Author: Decoded Intel
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:36:40 GMT
════════════════════════
⌗ Tags: #geopolitics #cybersecurity #africa #digital_payment #mauritania
Medium
Skipping Cash, Going Mobile
People who discuss global digital payment systems tend to focus on Western tap-to-pay systems and Asian super-app platforms. However, the…
⤷ Title: How to configure static IP address on Windows 10 with 2 easy methods
════════════════════════
𐀪 Author: Safelyo Global
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:33:38 GMT
════════════════════════
⌗ Tags: #safelyo #vpn #privacy #cybersecurity #technology
════════════════════════
𐀪 Author: Safelyo Global
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:33:38 GMT
════════════════════════
⌗ Tags: #safelyo #vpn #privacy #cybersecurity #technology
Medium
How to configure static IP address on Windows 10 with 2 easy methods
Are you trying to set up port forwarding for a game, keep a network printer reliably connected, or just take better control of your home…
⤷ Title: Keylogger project using Python
════════════════════════
𐀪 Author: The Commoness
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:31:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #information_security #keylogger #cyberattack
════════════════════════
𐀪 Author: The Commoness
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:31:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #information_security #keylogger #cyberattack
Medium
Keylogger project using Python
(Use this only for ethical and educational purpose project only )
⤷ Title: How to view history in DuckDuckGo: Step by step 2025 guide
════════════════════════
𐀪 Author: Millie Bobby
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:15:38 GMT
════════════════════════
⌗ Tags: #privacy #technology #cybersecurity #safelyo #vpn
════════════════════════
𐀪 Author: Millie Bobby
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:15:38 GMT
════════════════════════
⌗ Tags: #privacy #technology #cybersecurity #safelyo #vpn
Medium
How to view history in DuckDuckGo: Step by step 2025 guide
When I talk to people switching to privacy-focused browsers, one of the first points of confusion is always DuckDuckGo’s history. Users…
⤷ Title: 12 AWS IAM Security Leaks Hackers Look For (+ How to defend)
════════════════════════
𐀪 Author: Chris St. John
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:10:31 GMT
════════════════════════
⌗ Tags: #devops #aws_iam #aws #cloud_computing #cybersecurity
════════════════════════
𐀪 Author: Chris St. John
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:10:31 GMT
════════════════════════
⌗ Tags: #devops #aws_iam #aws #cloud_computing #cybersecurity
Medium
12 AWS IAM Security Leaks Hackers Look For (+ How to Defend)
Hunt down IAM misconfigurations before attackers turn your credentials into their playground
⤷ Title: The IoT Device That Wouldn’t Connect (And How I Fixed It)
════════════════════════
𐀪 Author: Odunze Jennifer Oluchukwu
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:00:46 GMT
════════════════════════
⌗ Tags: #network #cisco_packet_tracer #cisco #cybersecurity
════════════════════════
𐀪 Author: Odunze Jennifer Oluchukwu
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 01:00:46 GMT
════════════════════════
⌗ Tags: #network #cisco_packet_tracer #cisco #cybersecurity
Medium
The IoT Device That Wouldn’t Connect (And How I Fixed It)
Today, I built a small home network on Cisco Packet Tracer. I couldn’t get the wireless router to connect to the webcam, which is an IoT…
⤷ Title: First AI-Orchestrated Cyber-Espionage: Claude Code Executed 80%+ of China-Linked Intrusion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 04:00:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AICyberEspionage #Anthropic #AutonomousAI #ChinaThreat #ClaudeCode #cybersecurity #GTG1002 #MCP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 04:00:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AICyberEspionage #Anthropic #AutonomousAI #ChinaThreat #ClaudeCode #cybersecurity #GTG1002 #MCP
Penetration Testing Tools
First AI-Orchestrated Cyber-Espionage: Claude Code Executed 80%+ of China-Linked Intrusion
Anthropic confirmed the first AI-orchestrated cyber-espionage case: the China-linked GTG-1002 group used Claude Code to execute 80–90% of the intrusion cycle against 30 global targets.
⤷ Title: KMS38 Loophole Closed: Microsoft Finally Kills Offline Windows Activation Method
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:55:40 +0000
════════════════════════
⌗ Tags: #Technology #Windows #Activation #cybersecurity #gatherosstate.exe #KMS38 #Licensing #MASScript #Microsoft #Windows11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:55:40 +0000
════════════════════════
⌗ Tags: #Technology #Windows #Activation #cybersecurity #gatherosstate.exe #KMS38 #Licensing #MASScript #Microsoft #Windows11
Penetration Testing Tools
KMS38 Loophole Closed: Microsoft Finally Kills Offline Windows Activation Method
Microsoft closed the KMS38 loophole by removing gatherosstate.exe in Windows Build 26040, killing the offline method that granted Windows activation until 2038.
⤷ Title: C++20 Default: Red Hat Proposes Making the Latest Standard the Default in GCC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:47:43 +0000
════════════════════════
⌗ Tags: #Technology #C++17 #C++20 #Compiler #GCC #GNU++20 #MarekPolacek #Redhat #SoftwareDevelopment
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 03:47:43 +0000
════════════════════════
⌗ Tags: #Technology #C++17 #C++20 #Compiler #GCC #GNU++20 #MarekPolacek #Redhat #SoftwareDevelopment
Penetration Testing Tools
C++20 Default: Red Hat Proposes Making the Latest Standard the Default in GCC
Red Hat proposed making C++20 (GNU++20) the default language standard in GCC, replacing C++17. The shift may appear in a version after the upcoming GCC 16 release.