⤷ Title: Stealth Stealer: New .NET Loader Hides LokiBot Payload in BMP/PNG Images Using Advanced Steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:05:11 +0000
════════════════════════
⌗ Tags: #Malware #.NET Loader #BMP #Infostealer #Lokibot #PNG #Runtime Decryption #Splunk #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:05:11 +0000
════════════════════════
⌗ Tags: #Malware #.NET Loader #BMP #Infostealer #Lokibot #PNG #Runtime Decryption #Splunk #steganography
Daily CyberSecurity
Stealth Stealer: New .NET Loader Hides LokiBot Payload in BMP/PNG Images Using Advanced Steganography
Splunk uncovered a new .NET steganographic loader that hides LokiBot malware inside embedded BMP and PNG image files. The multi-stage loader uses a separate container module, evading static detection.
⤷ Title: macOS Wallet Stealer Uncovered: “Nova” Malware Replaces Ledger/Trezor Apps with Phishing Clones for Seed Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #LaunchAgent #Ledger Live #macOS #Modular Malware #phishing #Trezor Suite #Wallet Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:00:47 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #LaunchAgent #Ledger Live #macOS #Modular Malware #phishing #Trezor Suite #Wallet Stealer
Daily CyberSecurity
macOS Wallet Stealer Uncovered: "Nova" Malware Replaces Ledger/Trezor Apps with Phishing Clones for Seed Theft
A new macOS stealer (Nova) uses LaunchAgents to install a modular backdoor. Its main function is replacing legitimate Ledger/Trezor apps with phishing clones that exfiltrate seed phrases as users type.
⤷ Title: API2:2023 Broken Authentication: Critical API Identity Flaws and JWT Attacks
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:02:03 GMT
════════════════════════
⌗ Tags: #technology #hacking #cybersecurity #api #bug_bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:02:03 GMT
════════════════════════
⌗ Tags: #technology #hacking #cybersecurity #api #bug_bounty
Medium
API2:2023 Broken Authentication: Critical API Identity Flaws and JWT Attacks
Authentication failures, JWT token management, and mitigation. Detection of persistence and brute-force attacks.
⤷ Title: Metasploit Framework: Ingeniería Ofensiva desde la Vulnerabilidad hasta el Control Total
════════════════════════
𐀪 Author: Claudio Andres Sanjines Cuellar
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:24:35 GMT
════════════════════════
⌗ Tags: #ciberseguridad #ethical_hacking #metasploit #infosec #pentesting
════════════════════════
𐀪 Author: Claudio Andres Sanjines Cuellar
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:24:35 GMT
════════════════════════
⌗ Tags: #ciberseguridad #ethical_hacking #metasploit #infosec #pentesting
Medium
Metasploit Framework: Ingeniería Ofensiva desde la Vulnerabilidad hasta el Control Total
Introducción
⤷ Title: How to set up a local development environment for PHP 2025
════════════════════════
𐀪 Author: Safelyo Global
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:49:49 GMT
════════════════════════
⌗ Tags: #safelyo #cybersecurity #vpn #privacy #technology
════════════════════════
𐀪 Author: Safelyo Global
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:49:49 GMT
════════════════════════
⌗ Tags: #safelyo #cybersecurity #vpn #privacy #technology
Medium
How to set up a local development environment for PHP 2025
Building Your Digital Workshop: A Guide to Local PHP Environments
⤷ Title: The Day the Internet Felt Broken: What Really Happened During the November 2025 Cloud flare Outage…
════════════════════════
𐀪 Author: Athishsagarkishan
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:46:19 GMT
════════════════════════
⌗ Tags: #internet #error_handling #cloud_computing #cloudflare #cybersecurity
════════════════════════
𐀪 Author: Athishsagarkishan
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:46:19 GMT
════════════════════════
⌗ Tags: #internet #error_handling #cloud_computing #cloudflare #cybersecurity
Medium
The Day the Internet Felt Broken: What Really Happened During the November 2025 Cloud flare Outage…
It was November 18, 2025, and if you were working online, you probably remember that sudden, frustrating moment when websites just……
⤷ Title: China Used an AI Agent to Hack 30 Companies — and It Transforms Cybersecurity Forever
════════════════════════
𐀪 Author: Code Pulse
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:39:37 GMT
════════════════════════
⌗ Tags: #ai_agent #cybersecurity #ai #china #usa
════════════════════════
𐀪 Author: Code Pulse
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:39:37 GMT
════════════════════════
⌗ Tags: #ai_agent #cybersecurity #ai #china #usa
Medium
China Used an AI Agent to Hack 30 Companies — and It Transforms Cybersecurity Forever
In September 2025, an event occurred that the cybersecurity community had been predicting — and fearing — for years.
⤷ Title: Cloudflare Outage Briefly Takes Down Parts of the Internet — Including ChatGPT and X
════════════════════════
𐀪 Author: Theotismatthews
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:29:12 GMT
════════════════════════
⌗ Tags: #data_science #technology #cybersecurity #artificial_intelligence
════════════════════════
𐀪 Author: Theotismatthews
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:29:12 GMT
════════════════════════
⌗ Tags: #data_science #technology #cybersecurity #artificial_intelligence
Medium
Cloudflare Outage Briefly Takes Down Parts of the Internet — Including ChatGPT and X
Cloudflare Outage Briefly Takes Down Parts of the Internet — Including ChatGPT and X Earlier today, a widespread outage at Cloudflare — one of the world’s most critical internet …
⤷ Title: Listing the Database Contents on Non-Oracle Databases
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:21:51 GMT
════════════════════════
⌗ Tags: #web_app_security #burpsuite #cybernerddd #ethical_hacking #cybersecurity
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:21:51 GMT
════════════════════════
⌗ Tags: #web_app_security #burpsuite #cybernerddd #ethical_hacking #cybersecurity
Medium
Listing the Database Contents on Non-Oracle Databases
This is an SQL injection lab I exploited on PortSwigger.
The goal is to take advantage of the SQLi vulnerability inside the product…
The goal is to take advantage of the SQLi vulnerability inside the product…
⤷ Title: Cybersecurity for Teens: Protect Your Social Media
════════════════════════
𐀪 Author: Tech Tea with Navika
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:06:49 GMT
════════════════════════
⌗ Tags: #teenagers #crime #cyberbully #cybersecurity #cybercrime
════════════════════════
𐀪 Author: Tech Tea with Navika
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:06:49 GMT
════════════════════════
⌗ Tags: #teenagers #crime #cyberbully #cybersecurity #cybercrime
Medium
Cybersecurity for Teens: Protect Your Social Media
Belonging to the Era of Internet it is normal to be indulged in Social Media as Teenagers but that doesn’t mean it is Safe
⤷ Title: When Production Exposes Your Source Code: A Deep Dive into JavaScript Obfuscation
════════════════════════
𐀪 Author: Jaival Suthar
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #devops #web_development #aws #javascript
════════════════════════
𐀪 Author: Jaival Suthar
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:02:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #devops #web_development #aws #javascript
Medium
When Production Exposes Your Source Code: A Deep Dive into JavaScript Obfuscation
The deployment was live. Users were accessing the application seamlessly through CloudFront. Everything appeared perfect, until I opened…
⤷ Title: IoT, Endpoints, and the Silent War for Network Control: What SOC Teams Must Understand in 2025
════════════════════════
𐀪 Author: Spesh Billions
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:09:56 GMT
════════════════════════
⌗ Tags: #iot_security #endpoint_security #zero_trust #cybersecurity #threat_intelligence
════════════════════════
𐀪 Author: Spesh Billions
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 00:09:56 GMT
════════════════════════
⌗ Tags: #iot_security #endpoint_security #zero_trust #cybersecurity #threat_intelligence
Medium
🔐 IoT, Endpoints, and the Silent War for Network Control: What SOC Teams Must Understand in 2025
We are living in a world where everything from wristwatches to industrial turbines insists on being “smart.”
But behind all the smart…
But behind all the smart…
⤷ Title: GitLab CVE-2023–7028 | TryHackMe
════════════════════════
𐀪 Author: q1mthi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:34:26 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #vulnerability #exploitation #tryhackme #penetration_testing
════════════════════════
𐀪 Author: q1mthi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:34:26 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #vulnerability #exploitation #tryhackme #penetration_testing
Medium
GitLab CVE-2023–7028 | TryHackMe
A vulnerability that allows unauthorized users to take over user accounts, potentially including administrator accounts, without any…
⤷ Title: EchoEcho CTF Writeup — by vulnbydefault
════════════════════════
𐀪 Author: Bader ALmutairi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:05:48 GMT
════════════════════════
⌗ Tags: #ctf #rce #bypass #vulnbydefault #ctf_writeup
════════════════════════
𐀪 Author: Bader ALmutairi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:05:48 GMT
════════════════════════
⌗ Tags: #ctf #rce #bypass #vulnbydefault #ctf_writeup
Medium
💻 EchoEcho CTF Writeup — by vulnbydefault
السلام عليكم ورحمة الله
⤷ Title: CISA KEV Alert: FortiWeb RCE Flaw (CVE-2025-58034) Under Active Exploitation for Command Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:26:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58034 #FortiWeb #os command injection #rce #waf #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:26:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58034 #FortiWeb #os command injection #rce #waf #zero_day
Daily CyberSecurity
CISA KEV Alert: FortiWeb RCE Flaw (CVE-2025-58034) Under Active Exploitation for Command Injection
CISA added a FortiWeb RCE flaw (CVE-2025-58034) to its KEV Catalog due to active exploitation. The bug allows authenticated attackers to execute arbitrary code on the WAF via crafted requests. Update now.
⤷ Title: AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
Daily CyberSecurity
AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
Oligo exposed ShadowRay 2.0, a massive, evolving campaign using AI-generated malware to turn 230K exposed Ray AI clusters into a self-propagating cryptomining and DDoS botnet.
⤷ Title: D-Link DIR-878 Reaches EOL: 3 Unpatched RCE Flaws Allow Unauthenticated Remote Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #D_Link #DIR_878 #EOL #rce #router security #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #D_Link #DIR_878 #EOL #rce #router security #unauthenticated access
Daily CyberSecurity
D-Link DIR-878 Reaches EOL: 3 Unpatched RCE Flaws Allow Unauthenticated Remote Command Execution
D-Link warned that DIR-878 has reached EOL with three unpatched RCE flaws. Unauthenticated remote attackers can execute arbitrary commands via Dynamic DNS and DMZ settings due to insecure CGI parameters.
⤷ Title: Critical METZ CONNECT Flaws (CVSS 9.8) Allow Unauthenticated RCE and Admin Takeover on Industrial Controllers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:43:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_41734 #EWIO_2 #ICS #METZ CONNECT #rce #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:43:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_41734 #EWIO_2 #ICS #METZ CONNECT #rce #unauthenticated access
Daily CyberSecurity
Critical METZ CONNECT Flaws (CVSS 9.8) Allow Unauthenticated RCE and Admin Takeover on Industrial Controllers
METZ CONNECT patched five critical flaws in EWIO-2 industrial controllers. CVE-2025-41734 allows unauthenticated PHP RCE, and CVE-2025-41733 risks admin credential reset. Update to v2.2.0 immediately.
⤷ Title: 9 Million Installs: Malicious Chrome VPN Extensions Hijack User Traffic Via Remote PAC Proxy Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:23:16 +0000
════════════════════════
⌗ Tags: #Data Leak #Malware #Chrome extension #Chrome Web Store #LayerX #PAC Proxy #surveillance #Traffic Hijacking #VPN Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:23:16 +0000
════════════════════════
⌗ Tags: #Data Leak #Malware #Chrome extension #Chrome Web Store #LayerX #PAC Proxy #surveillance #Traffic Hijacking #VPN Malware
Daily CyberSecurity
9 Million Installs: Malicious Chrome VPN Extensions Hijack User Traffic Via Remote PAC Proxy Injection
LayerX exposed a 6-year, 9M-install campaign: Fake VPN/ad-blocking Chrome extensions hijack all user traffic via remote PAC proxy scripts, enabling surveillance and data exfiltration.
⤷ Title: Critical SolarWinds Serv-U Flaws (CVSS 9.1) Allow Authenticated Admin RCE and Path Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authenticated RCE #Critical Vulnerability #CVE_2025_40547 #Path Bypass #rce #SolarWinds Serv_U
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authenticated RCE #Critical Vulnerability #CVE_2025_40547 #Path Bypass #rce #SolarWinds Serv_U
Daily CyberSecurity
Critical SolarWinds Serv-U Flaws (CVSS 9.1) Allow Authenticated Admin RCE and Path Bypass
SolarWinds patched three Critical RCE flaws (CVSS 9.1) in Serv-U. An authenticated admin can exploit them for code execution and directory path bypass. Update to v15.5.3 immediately.
⤷ Title: npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
Daily CyberSecurity
npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
Socket exposed a new npm attack (dino_reborn) using Adspect cloaking to hide behind a fake crypto CAPTCHA for victims, while showing a polished decoy site (Offlido) to researchers.