⤷ Title: Data HTB Machine Walk-Through
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 22:13:30 GMT
════════════════════════
⌗ Tags: #htb_writeup #cybersecurity #path_traversal #ethical_hacking
════════════════════════
𐀪 Author: Nmullenski
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 22:13:30 GMT
════════════════════════
⌗ Tags: #htb_writeup #cybersecurity #path_traversal #ethical_hacking
Medium
Data HTB Machine Walk-Through
The Data machine is solved by exploiting CVE‑2021‑43798, a Grafana path traversal that lets you read its database file. Cracking the…
⤷ Title: Jeeves — HTB Writeups
════════════════════════
𐀪 Author: Alts
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 22:11:30 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #htb_walkthrough #hackthebox_writeup #htb_writeup #htb
════════════════════════
𐀪 Author: Alts
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 22:11:30 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #htb_walkthrough #hackthebox_writeup #htb_writeup #htb
Medium
Jeeves — HTB Writeups
Windows — Medium
⤷ Title: DOM Clobbering XSS — vulnbydefault Write-Up
════════════════════════
𐀪 Author: Bader ALmutairi
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 23:25:16 GMT
════════════════════════
⌗ Tags: #bypass #ctf #ctf_writeup #dom_clobbering #xss_vulnerability
════════════════════════
𐀪 Author: Bader ALmutairi
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 23:25:16 GMT
════════════════════════
⌗ Tags: #bypass #ctf #ctf_writeup #dom_clobbering #xss_vulnerability
Medium
🧠 DOM Clobbering XSS — vulnbydefault Write-Up
Introduction :
⤷ Title: How to integrate ReconFTW with KaliGPT
(or an LLM-assisted workflow)
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 22:39:17 GMT
════════════════════════
⌗ Tags: #recon #ai #kali_linux #kali_gpt #pentesting
(or an LLM-assisted workflow)
════════════════════════
𐀪 Author: ghostyjoe
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 22:39:17 GMT
════════════════════════
⌗ Tags: #recon #ai #kali_linux #kali_gpt #pentesting
Medium
How to integrate ReconFTW with KaliGPT (or an LLM-assisted workflow)
How to integrate ReconFTW with KaliGPT (or an LLM-assisted workflow) Short version: use ReconFTW to produce structured output, then feed…
⤷ Title: Critical W3 Total Cache Flaw (CVE-2025-9501, CVSS 9.0) Risks Unauthenticated RCE on 1 Million WordPress Sites
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:40:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #Critical RCE #CVE_2025_9501 #Unauthenticated Attack #W3 Total Cache #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:40:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #Critical RCE #CVE_2025_9501 #Unauthenticated Attack #W3 Total Cache #wordpress
Daily CyberSecurity
Critical W3 Total Cache Flaw (CVE-2025-9501, CVSS 9.0) Risks Unauthenticated RCE on 1 Million WordPress Sites
A Critical (CVSS 9.0) flaw in W3 Total Cache (CVE-2025-9501) allows unauthenticated attackers to execute arbitrary PHP code via a crafted comment. 1M+ sites are at risk. Update to v2.8.13.
⤷ Title: DOJ Seizes $15M in Crypto from APT38, Unveils Guilty Pleas in North Korean IT Worker Fraud Scheme
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:37:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT38 #Crypto Forfeiture #DOJ #DPRK IT workers #Lazarus Group #money laundering #North Korea #Wire Fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:37:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT38 #Crypto Forfeiture #DOJ #DPRK IT workers #Lazarus Group #money laundering #North Korea #Wire Fraud
Daily CyberSecurity
DOJ Seizes $15M in Crypto from APT38, Unveils Guilty Pleas in North Korean IT Worker Fraud Scheme
The DOJ announced five guilty pleas and $15M in crypto forfeiture seized from APT38. Facilitators helped North Korean IT workers fraudulently earn $2.2M from 136 US companies to fund the DPRK regime.
⤷ Title: Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:30:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #Cloudflare C2 #fileless backdoor #IRGC_IO #SpearSpecter #TAMECAT #WebDAV Abuse #WhatsApp Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:30:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT42 #Cloudflare C2 #fileless backdoor #IRGC_IO #SpearSpecter #TAMECAT #WebDAV Abuse #WhatsApp Espionage
Daily CyberSecurity
Iran APT SpearSpecter Uses Weeks-Long WhatsApp Lures and Fileless TAMECAT Backdoor to Hit Defense
Israel disclosed SpearSpecter: an IRGC-IO espionage campaign using weeks-long WhatsApp social engineering and search-ms/WebDAV abuse to deploy the fileless TAMECAT PowerShell backdoor with Discord/Telegram C2.
⤷ Title: Advanced macOS DigitStealer Targets M2+ Macs, Hijacking Ledger Live via JXA and DNS-Based C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:26:50 +0000
════════════════════════
⌗ Tags: #Malware #Apple Silicon #Cloudflare Pages #DigitStealer #DNS C2 #Infostealer #JXA #Ledger Live #macOS Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:26:50 +0000
════════════════════════
⌗ Tags: #Malware #Apple Silicon #Cloudflare Pages #DigitStealer #DNS C2 #Infostealer #JXA #Ledger Live #macOS Malware
Daily CyberSecurity
Advanced macOS DigitStealer Targets M2+ Macs, Hijacking Ledger Live via JXA and DNS-Based C2
Jamf exposed DigitStealer, an advanced macOS infostealer that checks for Apple M2+ chips. It uses Cloudflare Pages for delivery, JXA for stealth, and modifies Ledger Live to steal crypto wallets via DNS TXT C2.
⤷ Title: Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Malware #Chinese Campaign #DLL Sideloading #Gh0st RAT #Malware Distribution #Typosquatting #Unit 42 #VBScript
Daily CyberSecurity
Unit 42 Uncovers Two Massive Global Malware Campaigns Delivering Gh0st RAT Through Large-Scale Software Impersonation
Researchers at Palo Alto Networks Unit 42 have uncovered two expansive and interconnected malware campaigns active throughout 2025, both designed to mass-distribute Gh0st RAT variants to Chinese-s…
⤷ Title: Amatera Stealer Campaign Uses ClickFix to Deploy Malware, Bypassing EDR by Patching AMSI in Memory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Stealer #AMSI Bypass #ClickFix #Credential Theft #NetSupport RAT #powershell #Pure Crypter #WoW64 syscalls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Malware #Amatera Stealer #AMSI Bypass #ClickFix #Credential Theft #NetSupport RAT #powershell #Pure Crypter #WoW64 syscalls
Daily CyberSecurity
Amatera Stealer Campaign Uses ClickFix to Deploy Malware, Bypassing EDR by Patching AMSI in Memory
eSentire’s Threat Response Unit (TRU) has uncovered a widespread malware operation leveraging a deceptive social-engineering technique known as ClickFix to deliver a newly rebranded version of the…
⤷ Title: Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:05:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Defense Bypass #Dragon Breath #Gh0st RAT #Kernel Driver #PPL Abuse #Protected Process Light #RoningLoader
Daily CyberSecurity
Dragon Breath APT Deploys RoningLoader, Using Kernel Driver and PPL Abuse to Disable Windows Defender
Elastic exposed Dragon Breath APT's new RoningLoader malware. It uses PPL abuse and a signed kernel driver (ollama.sys) to disable Windows Defender and inject a modified gh0st RAT for espionage.
⤷ Title: CISA/Europol Warn: Akira Ransomware Profits Hit $244M, Group Expands to Encrypt Nutanix AHV VMs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:00:40 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #CISA #Double Extortion #Europol #Nutanix AHV #RaaS #virtualization #VPN Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:00:40 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #CISA #Double Extortion #Europol #Nutanix AHV #RaaS #virtualization #VPN Flaws
Daily CyberSecurity
CISA/Europol Warn: Akira Ransomware Profits Hit $244M, Group Expands to Encrypt Nutanix AHV VMs
CISA/Europol updated their advisory on Akira Ransomware, confirming $244M in profits. The group now encrypts Nutanix AHV VMs and performs data exfiltration in just two hours via VPN flaws.
⤷ Title: API2:2023 Broken Authentication: Fallos Críticos de Identidad en APIs y Ataques JWT
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:02:04 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #hacking #api #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:02:04 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #hacking #api #bug_bounty
Medium
API2:2023 Broken Authentication: Fallos Críticos de Identidad en APIs y Ataques JWT
Fallos en autenticación, gestión de tokens JWT y mitigación. Detección de ataques de persistencia y fuerza bruta.
⤷ Title: NTLM Relay: Red Team Network Abuse (and Why It Still Works in 2025)
════════════════════════
𐀪 Author: Yua Mikanana
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:05:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #penetration_testing #malware #red_team
════════════════════════
𐀪 Author: Yua Mikanana
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:05:22 GMT
════════════════════════
⌗ Tags: #cybersecurity #hacking #penetration_testing #malware #red_team
Medium
NTLM Relay: Red Team Network Abuse (and Why It Still Works in 2025)
If you’ve ever popped a shell on a Windows network without firing a single exploit — chances are, you’ve witnessed the dark magic of NTLM…
⤷ Title: THM - Shock and Silence
════════════════════════
𐀪 Author: Francesco Pastore
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:16:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #tech #hacking #technology
════════════════════════
𐀪 Author: Francesco Pastore
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:16:45 GMT
════════════════════════
⌗ Tags: #cybersecurity #security #tech #hacking #technology
Medium
THM - Shock and Silence
A writeup for “Shock and Silence” on TryHackMe.
⤷ Title: SOC127 — SQL Injection Detected (LetsDefend) — Professional Rewrite
════════════════════════
𐀪 Author: ahmed mostafa
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:40:43 GMT
════════════════════════
⌗ Tags: #lets_defend #siem #soc_analyst #cybersecurity #sql_attack
════════════════════════
𐀪 Author: ahmed mostafa
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:40:43 GMT
════════════════════════
⌗ Tags: #lets_defend #siem #soc_analyst #cybersecurity #sql_attack
Medium
SOC127 — SQL Injection Detected (LetsDefend) — Professional Rewrite
This alert walkthrough covers the full investigation of EventID 235, where a SQL Injection attempt was detected. Below is an enhanced and…
⤷ Title: OWASP Top 10 2025 — TryHackMe
════════════════════════
𐀪 Author: Mr.Cool
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:33:10 GMT
════════════════════════
⌗ Tags: #it_security #owasp_top_10 #cybersecurity #tryhackme #information_security
════════════════════════
𐀪 Author: Mr.Cool
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:33:10 GMT
════════════════════════
⌗ Tags: #it_security #owasp_top_10 #cybersecurity #tryhackme #information_security
Medium
OWASP Top 10 2025 — TryHackMe
IAAA Failures
⤷ Title: A Free Hands-On Threat Hunting Lab in Elastic SIEM
════════════════════════
𐀪 Author: Dhruv Patel
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:32:20 GMT
════════════════════════
⌗ Tags: #information_technology #information_security #elasticsearch #cybersecurity #cyber_security_training
════════════════════════
𐀪 Author: Dhruv Patel
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:32:20 GMT
════════════════════════
⌗ Tags: #information_technology #information_security #elasticsearch #cybersecurity #cyber_security_training
Medium
A Free Hands-On Threat Hunting Lab in Elastic SIEM
Most cybersecurity “labs” stop at screenshots and theory.
⤷ Title: Simple Cybersecurity Checklist
════════════════════════
𐀪 Author: LeakingElixir
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:28:45 GMT
════════════════════════
⌗ Tags: #seo #safety #technology #cybersecurity #data_security
════════════════════════
𐀪 Author: LeakingElixir
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 01:28:45 GMT
════════════════════════
⌗ Tags: #seo #safety #technology #cybersecurity #data_security
Medium
Simple Cybersecurity Checklist
Let’s jump right into it. Below are some simple checklists that every individual or business should follow. These fundamentals help protect…
⤷ Title: Web Security Essentials
════════════════════════
𐀪 Author: Demegorash
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:42:20 GMT
════════════════════════
⌗ Tags: #internet #blue_team #web_security #cybersecurity
════════════════════════
𐀪 Author: Demegorash
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:42:20 GMT
════════════════════════
⌗ Tags: #internet #blue_team #web_security #cybersecurity
Medium
Web Security Essentials
Learn how the web works, common website security risks, and protections for a safer internet.
⤷ Title: The AI Illusion: Why Companies Think They’re Safe- and Why They’re Not
════════════════════════
𐀪 Author: Diya mukherjee
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:42:10 GMT
════════════════════════
⌗ Tags: #ai_ethics #governance #cybersecurity #artificial_intelligence #compliance
════════════════════════
𐀪 Author: Diya mukherjee
════════════════════════
ⴵ Time: Tue, 18 Nov 2025 00:42:10 GMT
════════════════════════
⌗ Tags: #ai_ethics #governance #cybersecurity #artificial_intelligence #compliance
Medium
The AI Illusion: Why Companies Think They’re Safe- and Why They’re Not
It always happens the same way.