⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:06:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #AhnLab #APT #backdoor #CVE_2025_59287 #cyber attack #rce #security advisory #ShadowPad #Windows Server #WSUS
Daily CyberSecurity
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Backdoor
Threat actors are actively exploiting a new WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM shells and deploy the dangerous ShadowPad backdoor. Patch immediately!
⤷ Title: SonicWall Warns of New SonicOS SSLVPN Pre-Auth Buffer Overflow Vulnerability (CVE-2025-40601)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:01:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_40601 #Denial of Service #firewall #network_security #patch #SonicOS #SonicWall #SSLVPN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:01:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #CVE_2025_40601 #Denial of Service #firewall #network_security #patch #SonicOS #SonicWall #SSLVPN
Daily CyberSecurity
SonicWall Warns of New SonicOS SSLVPN Pre-Auth Buffer Overflow Vulnerability (CVE-2025-40601)
SonicWall reports a pre-auth stack-based buffer overflow flaw (CVE-2025-40601) in SonicOS SSLVPN, allowing remote DoS attacks. Patches and mitigation are available.
⤷ Title: Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 11:02:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 11:02:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: NHS Warns of PoC Exploit for 7-Zip Symbolic Link–Based RCE Vulnerability
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:57:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:57:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 13:35:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 13:35:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Sneaky 2FA Toolkit Upgraded: Uses ‘Browser-in-the-Browser’ to Steal Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:57:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser In The Browser #Credential Theft #cybersecurity #Microsoft Phishing #phishing #Push Security #Sneaky 2FA #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:57:56 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser In The Browser #Credential Theft #cybersecurity #Microsoft Phishing #phishing #Push Security #Sneaky 2FA #Social Engineering
Penetration Testing Tools
Sneaky 2FA Toolkit Upgraded: Uses 'Browser-in-the-Browser' to Steal Credentials
The Sneaky 2FA phishing toolkit now uses the Browser-in-the-Browser technique to create highly convincing fake login windows, making credential theft easier.
⤷ Title: LG Energy Solution Hacked: Akira Group Claims Theft of 1.7 TB of Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:53:48 +0000
════════════════════════
⌗ Tags: #Data Leak #Akira Ransomware #Battery Manufacturer #cyber attack #Data Theft #Extortion #FBI Advisory #LG Energy Solution #LG Energy Solution confirmed an overseas facility was hit by a cyber attack; the Akira ransomware group claims to have stolen a massive 1.7 TB of internal data. #Manufacturing Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:53:48 +0000
════════════════════════
⌗ Tags: #Data Leak #Akira Ransomware #Battery Manufacturer #cyber attack #Data Theft #Extortion #FBI Advisory #LG Energy Solution #LG Energy Solution confirmed an overseas facility was hit by a cyber attack; the Akira ransomware group claims to have stolen a massive 1.7 TB of internal data. #Manufacturing Security
Penetration Testing Tools
LG Energy Solution Hacked: Akira Group Claims Theft of 1.7 TB of Data
LG Energy Solution confirmed an overseas facility was hit by a cyber attack; the Akira ransomware group claims to have stolen a massive 1.7 TB of internal data.
⤷ Title: Samsung AppCloud Sparks Privacy Fear: Accused of Being ‘Undeletable Spyware’
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:51:17 +0000
════════════════════════
⌗ Tags: #Malware #Android #AppCloud #Digital Rights #ironSource #pre_installed apps #Privacy Concern #Samsung Galaxy #Spyware #System Permissions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:51:17 +0000
════════════════════════
⌗ Tags: #Malware #Android #AppCloud #Digital Rights #ironSource #pre_installed apps #Privacy Concern #Samsung Galaxy #Spyware #System Permissions
Penetration Testing Tools
Samsung AppCloud Sparks Privacy Fear: Accused of Being 'Undeletable Spyware'
Controversy hits Samsung's budget Galaxy phones over the pre-installed AppCloud service (from ironSource), which critics label "undeletable spyware" with system-level access.
⤷ Title: Cloudflare Outage: Internal Failure Shuts Down Sites, Exposing Hidden Security Gaps
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:29:05 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Bot Management #Cloudflare #cybersecurity #DDoS protection #internet infrastructure #Outage #Security Perimeter #Single Point of Failure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:29:05 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Bot Management #Cloudflare #cybersecurity #DDoS protection #internet infrastructure #Outage #Security Perimeter #Single Point of Failure
Penetration Testing Tools
Cloudflare Outage: Internal Failure Shuts Down Sites, Exposing Hidden Security Gaps
A database error in Cloudflare's Bot Management system caused a global outage, forcing sites to run without security filtering and renewing single point of failure risks.
⤷ Title: Xubuntu Download Page Hacked: Malicious File Distributed for Several Days
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:22:59 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force Attack #Canonical #Download Page #Linux distribution #malware #security incident #WordPress Vulnerability #Xubuntu
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:22:59 +0000
════════════════════════
⌗ Tags: #Malware #Brute Force Attack #Canonical #Download Page #Linux distribution #malware #security incident #WordPress Vulnerability #Xubuntu
Penetration Testing Tools
Xubuntu Download Page Hacked: Malicious File Distributed for Several Days
The Xubuntu download page was compromised via a WordPress brute-force attack, leading to the distribution of a malicious file for four days. The site is now secured.
⤷ Title: New Sturnus Android Trojan Bypasses Signal/WhatsApp Encryption, Seizes Full Control
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:15:05 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Encryption Bypass #mobile security #Overlay Attack #Signal #Sturnus #ThreatFabric #VNC #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:15:05 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #banking trojan #Encryption Bypass #mobile security #Overlay Attack #Signal #Sturnus #ThreatFabric #VNC #WhatsApp
Penetration Testing Tools
New Sturnus Android Trojan Bypasses Signal/WhatsApp Encryption, Seizes Full Control
Sturnus is a new Android banking trojan that captures decrypted Signal/WhatsApp messages, performs overlay attacks, and uses VNC for full, remote device takeover.
⤷ Title: MEMINSPECT Proposed for Linux Kernel: Simplifies Memory Debugging & Post-Mortem Analysis
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:11:53 +0000
════════════════════════
⌗ Tags: #Linux #embedded systems #Kernel Development #Linaro #Linux Kernel #LKML #MEMINSPECT #Memory Debugging #Post_Mortem Analysis
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 09:11:53 +0000
════════════════════════
⌗ Tags: #Linux #embedded systems #Kernel Development #Linaro #Linux Kernel #LKML #MEMINSPECT #Memory Debugging #Post_Mortem Analysis
Penetration Testing Tools
MEMINSPECT Proposed for Linux Kernel: Simplifies Memory Debugging & Post-Mortem Analysis
The MEMINSPECT mechanism has been proposed for the Linux kernel to simplify memory analysis in constrained systems, enabling reduced post-mortem memory dumps.
⤷ Title: Google Cracks AirDrop: Pixel 10 Enables Seamless File Sharing with iPhone
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 08:59:54 +0000
════════════════════════
⌗ Tags: #Android #Google #AirDrop #Apple #File Transfer #Interoperability #ios #Pixel 10 #Quick Share #Tech News #Walled Garden
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 08:59:54 +0000
════════════════════════
⌗ Tags: #Android #Google #AirDrop #Apple #File Transfer #Interoperability #ios #Pixel 10 #Quick Share #Tech News #Walled Garden
Penetration Testing Tools
Google Cracks AirDrop: Pixel 10 Enables Seamless File Sharing with iPhone
Google unilaterally enabled Quick Share/AirDrop interoperability on the Pixel 10, allowing seamless two-way file transfers with iPhones and Macs. The future of sharing is here!
⤷ Title: BitlockMove: New PoC for Covert Lateral Movement via BitLocker DCOM Hijacking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:32:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BitlockMove #COM Hijacking #cybersecurity #DCOM #Defensive Telemetry #Lateral Movement #Proof of Concept #Red Team #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:32:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BitlockMove #COM Hijacking #cybersecurity #DCOM #Defensive Telemetry #Lateral Movement #Proof of Concept #Red Team #Windows Security
Penetration Testing Tools
BitlockMove: New PoC for Covert Lateral Movement via BitLocker DCOM Hijacking
"BitlockMove" PoC demonstrates a novel lateral movement technique abusing BitLocker DCOM/COM hijacking to execute code in a logged-in user's session without credential theft.
⤷ Title: AMD Patches Hint at Next-Gen RDNA 5 or Enhanced GPU Architecture in Linux Driver
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:27:51 +0000
════════════════════════
⌗ Tags: #Linux #Technology #AMD #AMDGPU #GFXHUB 12.1 #GPU #Hardware News #Kernel Development #Linux driver #RDNA 4 #RDNA 5
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:27:51 +0000
════════════════════════
⌗ Tags: #Linux #Technology #AMD #AMDGPU #GFXHUB 12.1 #GPU #Hardware News #Kernel Development #Linux driver #RDNA 4 #RDNA 5
Penetration Testing Tools
AMD Patches Hint at Next-Gen RDNA 5 or Enhanced GPU Architecture in Linux Driver
AMD is adding support for mysterious new GPUs (GFXHUB 12.1) to the Linux driver, suggesting either a refined RDNA 4 design or the unannounced next-gen RDNA 5/UDNA architecture.
⤷ Title: Microsoft Integrates Sysmon Natively into Windows 11 & Server 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:25:18 +0000
════════════════════════
⌗ Tags: #Windows #Incident Response #Microsoft #Secure Future Initiative #Security Telemetry #security tool #SIEM #Sysmon #Windows 11 #Windows Server 2025
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:25:18 +0000
════════════════════════
⌗ Tags: #Windows #Incident Response #Microsoft #Secure Future Initiative #Security Telemetry #security tool #SIEM #Sysmon #Windows 11 #Windows Server 2025
Penetration Testing Tools
Microsoft Integrates Sysmon Natively into Windows 11 & Server 2025
Sysmon capabilities are now natively integrated into Windows 11 and Server 2025, providing built-in security telemetry for process and network monitoring via Windows Update.
⤷ Title: Operation WrtHug: 50,000+ Outdated ASUS Routers Hacked for Covert Botnet
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:22:52 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #AiCloud #ASUS Routers #BOTNET #China APT #cyber attack #network security #Outdated Firmware #SecurityScorecard #WrtHug
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:22:52 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #AiCloud #ASUS Routers #BOTNET #China APT #cyber attack #network security #Outdated Firmware #SecurityScorecard #WrtHug
Penetration Testing Tools
Operation WrtHug: 50,000+ Outdated ASUS Routers Hacked for Covert Botnet
Operation WrtHug compromised over 50,000 outdated ASUS routers (RT-AC, DSL-AC series) using old flaws to build a covert botnet, likely linked to Chinese threat actors.
⤷ Title: FortiWeb Alert: New Authenticated Command Injection Flaw (CVE-2025-58034) Actively Exploited
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:19:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #Command Injection #CVE_2025_58034 #Fortinet #FortiWeb #network security #Patch #RCE #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:19:26 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #Command Injection #CVE_2025_58034 #Fortinet #FortiWeb #network security #Patch #RCE #vulnerability
Penetration Testing Tools
FortiWeb Alert: New Authenticated Command Injection Flaw (CVE-2025-58034) Actively Exploited
Fortinet confirms a new, actively exploited command injection flaw (CVE-2025-58034) in FortiWeb, which CISA mandates be patched within 7 days. Update immediately!
⤷ Title: Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:18:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip #CVE_2025_11001 #remote code execution #Security Advisory #Symlink #vulnerability #windows #ZIP File
Penetration Testing Tools
Urgent Patch: 7-Zip Flaw (CVE-2025-11001) Actively Exploited for Code Execution
NHS Digital warns that a high-severity 7-Zip symbolic link flaw (CVE-2025-11001) is being actively weaponized to execute arbitrary code. Update to 7-Zip 25.00 now!
⤷ Title: ShadowRay 2.0: AI Orchestration Framework Ray Hacked for Autonomous Cryptojacking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:14:07 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #AI Cluster #Cryptojacking #CVE_2023_48022 #cybersecurity #GPU Mining #misconfiguration #Ray Framework #RCE #ShadowRay
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 10:14:07 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #AI Cluster #Cryptojacking #CVE_2023_48022 #cybersecurity #GPU Mining #misconfiguration #Ray Framework #RCE #ShadowRay
Penetration Testing Tools
ShadowRay 2.0: AI Orchestration Framework Ray Hacked for Autonomous Cryptojacking
The ShadowRay 2.0 campaign exploits the unauthenticated Ray Jobs API (CVE-2023-48022) in over 200,000 exposed instances to deploy a self-propagating cryptomining botnet.
⤷ Title: Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 18:30:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 18:30:00 +0530
════════════════════════
⌗ Tags: No_Tags
❤1