⤷ Title: Salesforce Revokes Access Tokens: Gainsight App Breach May Have Exposed Customer Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 02:58:47 +0000
════════════════════════
⌗ Tags: #Data Leak #AppExchange #Cloud Security #CRM #Data Breach #Gainsight #OAuth Token #Salesforce #security alert #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 02:58:47 +0000
════════════════════════
⌗ Tags: #Data Leak #AppExchange #Cloud Security #CRM #Data Breach #Gainsight #OAuth Token #Salesforce #security alert #supply chain attack
Daily CyberSecurity
Salesforce Revokes Access Tokens: Gainsight App Breach May Have Exposed Customer Data
Salesforce revoked all Gainsight app tokens and removed the app from the AppExchange after finding unusual activity that may have exposed customer data via the connection.
⤷ Title: Sturnus Trojan Bypasses WhatsApp/Signal Encryption & Takes Over Android Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:11:30 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #cybersecurity news #Device Takeover #Encrypted Messaging Bypass #mobile security #MTI Security #Sturnus #ThreatFabric
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:11:30 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #cybersecurity news #Device Takeover #Encrypted Messaging Bypass #mobile security #MTI Security #Sturnus #ThreatFabric
Daily CyberSecurity
Sturnus Trojan Bypasses WhatsApp/Signal Encryption & Takes Over Android Devices
The new Sturnus Android banking trojan bypasses end-to-end encryption on WhatsApp & Signal and enables full device takeover for hidden financial fraud.
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
Daily CyberSecurity
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
Threat actors are actively exploiting a new WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM shells and deploy the dangerous ShadowPad backdoor. Patch immediately!
⤷ Title: SonicWall Warns of New SonicOS SSLVPN Pre-Auth Buffer Overflow Vulnerability (CVE-2025-40601)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:01:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_40601 #Denial of Service #firewall #network_security #patch #SonicOS #SonicWall #SSLVPN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:01:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_40601 #Denial of Service #firewall #network_security #patch #SonicOS #SonicWall #SSLVPN
Daily CyberSecurity
SonicWall Warns of New SonicOS SSLVPN Pre-Auth Buffer Overflow Vulnerability (CVE-2025-40601)
SonicWall reports a pre-auth stack-based buffer overflow flaw (CVE-2025-40601) in SonicOS SSLVPN, allowing remote DoS attacks. Patches and mitigation are available.
⤷ Title: Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 11:02:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 11:02:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: NHS Warns of PoC Exploit for 7-Zip Symbolic Link–Based RCE Vulnerability
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:57:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:57:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 13:35:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 13:35:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Sneaky 2FA Toolkit Upgraded: Uses ‘Browser-in-the-Browser’ to Steal Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:57:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser In The Browser #Credential Theft #cybersecurity #Microsoft Phishing #phishing #Push Security #Sneaky 2FA #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:57:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser In The Browser #Credential Theft #cybersecurity #Microsoft Phishing #phishing #Push Security #Sneaky 2FA #Social Engineering
Penetration Testing Tools
Sneaky 2FA Toolkit Upgraded: Uses 'Browser-in-the-Browser' to Steal Credentials
The Sneaky 2FA phishing toolkit now uses the Browser-in-the-Browser technique to create highly convincing fake login windows, making credential theft easier.
⤷ Title: LG Energy Solution Hacked: Akira Group Claims Theft of 1.7 TB of Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:53:48 +0000
════════════════════════
⌗ Tags: #Data Leak #Akira Ransomware #Battery Manufacturer #cyber attack #Data Theft #Extortion #FBI Advisory #LG Energy Solution #LG Energy Solution confirmed an overseas facility was hit by a cyber attack; the Akira ransomware group claims to have stolen a massive 1.7 TB of internal data. #Manufacturing Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:53:48 +0000
════════════════════════
⌗ Tags: #Data Leak #Akira Ransomware #Battery Manufacturer #cyber attack #Data Theft #Extortion #FBI Advisory #LG Energy Solution #LG Energy Solution confirmed an overseas facility was hit by a cyber attack; the Akira ransomware group claims to have stolen a massive 1.7 TB of internal data. #Manufacturing Security
Penetration Testing Tools
LG Energy Solution Hacked: Akira Group Claims Theft of 1.7 TB of Data
LG Energy Solution confirmed an overseas facility was hit by a cyber attack; the Akira ransomware group claims to have stolen a massive 1.7 TB of internal data.
⤷ Title: Samsung AppCloud Sparks Privacy Fear: Accused of Being ‘Undeletable Spyware’
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:51:17 +0000
════════════════════════
⌗ Tags: #Malware #Android #AppCloud #Digital Rights #ironSource #pre_installed apps #Privacy Concern #Samsung Galaxy #Spyware #System Permissions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:51:17 +0000
════════════════════════
⌗ Tags: #Malware #Android #AppCloud #Digital Rights #ironSource #pre_installed apps #Privacy Concern #Samsung Galaxy #Spyware #System Permissions
Penetration Testing Tools
Samsung AppCloud Sparks Privacy Fear: Accused of Being 'Undeletable Spyware'
Controversy hits Samsung's budget Galaxy phones over the pre-installed AppCloud service (from ironSource), which critics label "undeletable spyware" with system-level access.
⤷ Title: Cloudflare Outage: Internal Failure Shuts Down Sites, Exposing Hidden Security Gaps
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:29:05 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Bot Management #Cloudflare #cybersecurity #DDoS protection #internet infrastructure #Outage #Security Perimeter #Single Point of Failure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:29:05 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Bot Management #Cloudflare #cybersecurity #DDoS protection #internet infrastructure #Outage #Security Perimeter #Single Point of Failure
Penetration Testing Tools
Cloudflare Outage: Internal Failure Shuts Down Sites, Exposing Hidden Security Gaps
A database error in Cloudflare's Bot Management system caused a global outage, forcing sites to run without security filtering and renewing single point of failure risks.
⤷ Title: Xubuntu Download Page Hacked: Malicious File Distributed for Several Days
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:22:59 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force Attack #Canonical #Download Page #Linux distribution #malware #security incident #WordPress Vulnerability #Xubuntu
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:22:59 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force Attack #Canonical #Download Page #Linux distribution #malware #security incident #WordPress Vulnerability #Xubuntu
Penetration Testing Tools
Xubuntu Download Page Hacked: Malicious File Distributed for Several Days
The Xubuntu download page was compromised via a WordPress brute-force attack, leading to the distribution of a malicious file for four days. The site is now secured.
⤷ Title: New Sturnus Android Trojan Bypasses Signal/WhatsApp Encryption, Seizes Full Control
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:15:05 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Encryption Bypass #mobile security #Overlay Attack #Signal #Sturnus #ThreatFabric #VNC #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:15:05 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Encryption Bypass #mobile security #Overlay Attack #Signal #Sturnus #ThreatFabric #VNC #WhatsApp
Penetration Testing Tools
New Sturnus Android Trojan Bypasses Signal/WhatsApp Encryption, Seizes Full Control
Sturnus is a new Android banking trojan that captures decrypted Signal/WhatsApp messages, performs overlay attacks, and uses VNC for full, remote device takeover.
⤷ Title: MEMINSPECT Proposed for Linux Kernel: Simplifies Memory Debugging & Post-Mortem Analysis
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:11:53 +0000
════════════════════════
⌗ Tags: #Linux #embedded systems #Kernel Development #Linaro #Linux Kernel #LKML #MEMINSPECT #Memory Debugging #Post_Mortem Analysis
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:11:53 +0000
════════════════════════
⌗ Tags: #Linux #embedded systems #Kernel Development #Linaro #Linux Kernel #LKML #MEMINSPECT #Memory Debugging #Post_Mortem Analysis
Penetration Testing Tools
MEMINSPECT Proposed for Linux Kernel: Simplifies Memory Debugging & Post-Mortem Analysis
The MEMINSPECT mechanism has been proposed for the Linux kernel to simplify memory analysis in constrained systems, enabling reduced post-mortem memory dumps.
⤷ Title: Google Cracks AirDrop: Pixel 10 Enables Seamless File Sharing with iPhone
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 08:59:54 +0000
════════════════════════
⌗ Tags: #Android #Google #AirDrop #Apple #File Transfer #Interoperability #ios #Pixel 10 #Quick Share #Tech News #Walled Garden
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 08:59:54 +0000
════════════════════════
⌗ Tags: #Android #Google #AirDrop #Apple #File Transfer #Interoperability #ios #Pixel 10 #Quick Share #Tech News #Walled Garden
Penetration Testing Tools
Google Cracks AirDrop: Pixel 10 Enables Seamless File Sharing with iPhone
Google unilaterally enabled Quick Share/AirDrop interoperability on the Pixel 10, allowing seamless two-way file transfers with iPhones and Macs. The future of sharing is here!
⤷ Title: BitlockMove: New PoC for Covert Lateral Movement via BitLocker DCOM Hijacking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:32:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BitlockMove #COM Hijacking #cybersecurity #DCOM #Defensive Telemetry #Lateral Movement #Proof of Concept #Red Team #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:32:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BitlockMove #COM Hijacking #cybersecurity #DCOM #Defensive Telemetry #Lateral Movement #Proof of Concept #Red Team #Windows Security
Penetration Testing Tools
BitlockMove: New PoC for Covert Lateral Movement via BitLocker DCOM Hijacking
"BitlockMove" PoC demonstrates a novel lateral movement technique abusing BitLocker DCOM/COM hijacking to execute code in a logged-in user's session without credential theft.
⤷ Title: AMD Patches Hint at Next-Gen RDNA 5 or Enhanced GPU Architecture in Linux Driver
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:27:51 +0000
════════════════════════
⌗ Tags: #Linux #Technology #AMD #AMDGPU #GFXHUB 12.1 #GPU #Hardware News #Kernel Development #Linux driver #RDNA 4 #RDNA 5
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:27:51 +0000
════════════════════════
⌗ Tags: #Linux #Technology #AMD #AMDGPU #GFXHUB 12.1 #GPU #Hardware News #Kernel Development #Linux driver #RDNA 4 #RDNA 5
Penetration Testing Tools
AMD Patches Hint at Next-Gen RDNA 5 or Enhanced GPU Architecture in Linux Driver
AMD is adding support for mysterious new GPUs (GFXHUB 12.1) to the Linux driver, suggesting either a refined RDNA 4 design or the unannounced next-gen RDNA 5/UDNA architecture.
⤷ Title: Microsoft Integrates Sysmon Natively into Windows 11 & Server 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:25:18 +0000
════════════════════════
⌗ Tags: #Windows #Incident Response #Microsoft #Secure Future Initiative #Security Telemetry #security tool #SIEM #Sysmon #Windows 11 #Windows Server 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:25:18 +0000
════════════════════════
⌗ Tags: #Windows #Incident Response #Microsoft #Secure Future Initiative #Security Telemetry #security tool #SIEM #Sysmon #Windows 11 #Windows Server 2025
Penetration Testing Tools
Microsoft Integrates Sysmon Natively into Windows 11 & Server 2025
Sysmon capabilities are now natively integrated into Windows 11 and Server 2025, providing built-in security telemetry for process and network monitoring via Windows Update.
⤷ Title: Operation WrtHug: 50,000+ Outdated ASUS Routers Hacked for Covert Botnet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:22:52 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #AiCloud #ASUS Routers #BOTNET #China APT #cyber attack #network security #Outdated Firmware #SecurityScorecard #WrtHug
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:22:52 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #AiCloud #ASUS Routers #BOTNET #China APT #cyber attack #network security #Outdated Firmware #SecurityScorecard #WrtHug
Penetration Testing Tools
Operation WrtHug: 50,000+ Outdated ASUS Routers Hacked for Covert Botnet
Operation WrtHug compromised over 50,000 outdated ASUS routers (RT-AC, DSL-AC series) using old flaws to build a covert botnet, likely linked to Chinese threat actors.
⤷ Title: FortiWeb Alert: New Authenticated Command Injection Flaw (CVE-2025-58034) Actively Exploited
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:19:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #Command Injection #CVE_2025_58034 #Fortinet #FortiWeb #network security #Patch #RCE #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:19:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #Command Injection #CVE_2025_58034 #Fortinet #FortiWeb #network security #Patch #RCE #vulnerability
Penetration Testing Tools
FortiWeb Alert: New Authenticated Command Injection Flaw (CVE-2025-58034) Actively Exploited
Fortinet confirms a new, actively exploited command injection flaw (CVE-2025-58034) in FortiWeb, which CISA mandates be patched within 7 days. Update immediately!
⤷ Title: Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
Penetration Testing Tools
Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
NHS Digital warns that a high-severity 7-Zip symbolic link flaw (CVE-2025-11001) is being actively weaponized to execute arbitrary code. Update to 7-Zip 25.00 now!