⤷ Title: Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 21:10:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 21:10:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: ShinyHunters Breach Gainsight Apps on Salesforce, Claim Data from 1000 Firms
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 15:24:13 +0000
════════════════════════
⌗ Tags: #Hacking News #Security #Cyber Attack #Cybersecurity #data breach #Gainsight #Privacy #Salesforce #ShinyHunters
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 15:24:13 +0000
════════════════════════
⌗ Tags: #Hacking News #Security #Cyber Attack #Cybersecurity #data breach #Gainsight #Privacy #Salesforce #ShinyHunters
Hackread
ShinyHunters Breach Gainsight Apps on Salesforce, Claim Data from 1000 Firms
ShinyHunters breached Gainsight apps integrated with Salesforce, claiming access to data from 1000 firms using stolen credentials and compromised tokens.
⤷ Title: Intigriti Bug Bytes #230 - November 2025 🚀
════════════════════════
𐀪 Author: Ayoub
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
════════════════════════
𐀪 Author: Ayoub
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Bug Bytes
Intigriti
Intigriti Bug Bytes #230 - November 2025 🚀
Hi hackers, Welcome to the latest edition of Bug Bytes! In this month’s issue, we’ll be featuring: Finding an RCE using AI in GitHub CORS exploitation cheat sheet Scanning codebases with AI Bypass...
⤷ Title: New Sturnus Android Malware Reads WhatsApp, Telegram, Signal Chats via Accessibility Abuse
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 16:52:43 +0000
════════════════════════
⌗ Tags: #Android #Malware #Security #Cybersecurity #Encryption #Privacy #Signal #Sturnus #Telegram #WhatsApp
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 21 Nov 2025 16:52:43 +0000
════════════════════════
⌗ Tags: #Android #Malware #Security #Cybersecurity #Encryption #Privacy #Signal #Sturnus #Telegram #WhatsApp
Hackread
New Sturnus Android Malware Reads WhatsApp, Telegram, Signal Chats via Accessibility Abuse
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Trojanized VPN Installer Deploys NKNShell Backdoor, Using P2P Blockchain and MQTT Protocols for Covert C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:10:21 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain Protocol #Go malware #MQTT #NKNShell #P2P C2 #Supply Chain #VPN Installer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:10:21 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #Blockchain Protocol #Go malware #MQTT #NKNShell #P2P C2 #Supply Chain #VPN Installer
Daily CyberSecurity
Trojanized VPN Installer Deploys NKNShell Backdoor, Using P2P Blockchain and MQTT Protocols for Covert C2
ASEC exposed a VPN supply chain attack deploying NKNShell, a Go-based backdoor that uses P2P NKN and MQTT for stealthy C2. The installer bypasses AMSI using AI-generated code and grants full remote access (MeshAgent, gs-netcat).
⤷ Title: SonicWall Patches Two Vulnerabilities in Email Security Appliances, Including Code Execution Flaw (CVE-2025-40604)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Integrity Bypass #CVE_2025_40604 #Email Security #Path Traversal #rce #SonicWall #VM Tampering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 00:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Integrity Bypass #CVE_2025_40604 #Email Security #Path Traversal #rce #SonicWall #VM Tampering
Daily CyberSecurity
SonicWall Patches Two Vulnerabilities in Email Security Appliances, Including Code Execution Flaw (CVE-2025-40604)
SonicWall patched a critical flaw (CVE-2025-40604) in its Email Security appliances. The bug allows persistent RCE by exploiting a lack of integrity checks when loading the root filesystem image from the VM datastore.
⤷ Title: Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 12:17:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 12:17:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 12:15:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 12:15:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 20:49:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 20:49:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: CrowdStrike Fires Worker Over Insider Leak to Scattered Lapsus Hunters
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 16:13:19 +0000
════════════════════════
⌗ Tags: #Cyber Crime #CrowdStrike #Cybersecurity #Insider Threat #Scattered Lapsus Hunters #ShinyHunters
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 22 Nov 2025 16:13:19 +0000
════════════════════════
⌗ Tags: #Cyber Crime #CrowdStrike #Cybersecurity #Insider Threat #Scattered Lapsus Hunters #ShinyHunters
Hackread
CrowdStrike Fires Worker Over Insider Leak to Scattered Lapsus Hunters
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: LdrShuffle: Stealthy Code Execution via DLL EntryPoint Overwriting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:27:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Code Execution #Defensive Telemetry #DLL hijacking #Lateral Movement #LdrShuffle #Memory Injection #Red Team #Windows Loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:27:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Code Execution #Defensive Telemetry #DLL hijacking #Lateral Movement #LdrShuffle #Memory Injection #Red Team #Windows Loader
Penetration Testing Tools
LdrShuffle: Stealthy Code Execution via DLL EntryPoint Overwriting
"LdrShuffle" is a stealthy code execution technique that abuses the Windows Loader by overwriting a DLL's EntryPoint, enabling injection without creating new threads.
⤷ Title: Grok Goes Full Fanboy: Chatbot’s Absurd Bias Towards Elon Musk Goes Viral
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:24:31 +0000
════════════════════════
⌗ Tags: #Technology #AI Bias #Chatbot #Elon Musk #Generative AI #Grok #System Prompt #Tech Controversy #X #xAI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:24:31 +0000
════════════════════════
⌗ Tags: #Technology #AI Bias #Chatbot #Elon Musk #Generative AI #Grok #System Prompt #Tech Controversy #X #xAI
Penetration Testing Tools
Grok Goes Full Fanboy: Chatbot’s Absurd Bias Towards Elon Musk Goes Viral
The X-integrated Grok chatbot has gone viral for attributing absurd, fantastical abilities to Elon Musk. The bias appears confined to the public version of the model.
⤷ Title: TamperedChef Campaign Uses Forged Certificates to Distribute Malware via Fake Installers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:21:10 +0000
════════════════════════
⌗ Tags: #Malware #Acronis #cybercrime #EvilAI #Fake Installers #Forged Certificates #malware #Social Engineering #TamperedChef
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:21:10 +0000
════════════════════════
⌗ Tags: #Malware #Acronis #cybercrime #EvilAI #Fake Installers #Forged Certificates #malware #Social Engineering #TamperedChef
Penetration Testing Tools
TamperedChef Campaign Uses Forged Certificates to Distribute Malware via Fake Installers
The TamperedChef malware campaign is actively distributing payloads via fake software installers and forged digital certificates, primarily targeting users searching for utilities.
⤷ Title: Tsundere Botnet Masquerades as Valorant/CS2, Uses Ethereum Smart Contract for C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:18:06 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #Command and Control #cybersecurity #Ethereum #Gaming Malware #kaspersky #Node.js #Smart Contract #Tsundere
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:18:06 +0000
════════════════════════
⌗ Tags: #Malware #BOTNET #Command and Control #cybersecurity #Ethereum #Gaming Malware #kaspersky #Node.js #Smart Contract #Tsundere
Penetration Testing Tools
Tsundere Botnet Masquerades as Valorant/CS2, Uses Ethereum Smart Contract for C2
The Tsundere botnet targets gamers via fake MSI installers, using a unique method: fetching its Command-and-Control server address from an Ethereum smart contract.
⤷ Title: Forty-Fold Spike in Probing Targets Palo Alto GlobalProtect Login Portals
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #cybersecurity #GlobalProtect #GreyNoise #Palo Alto Networks #Scanning Campaign #VPN #Vulnerability Probing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #cybersecurity #GlobalProtect #GreyNoise #Palo Alto Networks #Scanning Campaign #VPN #Vulnerability Probing
Penetration Testing Tools
Forty-Fold Spike in Probing Targets Palo Alto GlobalProtect Login Portals
GreyNoise recorded a 40x spike in automated requests hitting Palo Alto GlobalProtect portals, a pattern that historically precedes the disclosure or exploitation of new vulnerabilities.
⤷ Title: Google Gemini Gets New Image Verification Tool to Detect AI-Generated Content
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:15:06 +0000
════════════════════════
⌗ Tags: #Google #AI Generative #AI Watermark #C2PA #Deepfake Detection #Google Gemini #Image Verification #Nano Banana Pro #SynthID
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:15:06 +0000
════════════════════════
⌗ Tags: #Google #AI Generative #AI Watermark #C2PA #Deepfake Detection #Google Gemini #Image Verification #Nano Banana Pro #SynthID
Penetration Testing Tools
Google Gemini Gets New Image Verification Tool to Detect AI-Generated Content
Google integrated a new image verification tool into Gemini, using the invisible SynthID watermark to detect content created by Google's AI models, though limitations exist.
⤷ Title: Google Unveils Nano Banana Pro: 4K AI Images, Perfect Text, and Gemini 3 Core
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:10:22 +0000
════════════════════════
⌗ Tags: #Google #4K Resolution #AI Image Generation #Controllability #Gemini 3 #Generative AI #google #Nano Banana Pro #Text Rendering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:10:22 +0000
════════════════════════
⌗ Tags: #Google #4K Resolution #AI Image Generation #Controllability #Gemini 3 #Generative AI #google #Nano Banana Pro #Text Rendering
Penetration Testing Tools
Google Unveils Nano Banana Pro: 4K AI Images, Perfect Text, and Gemini 3 Core
Google's Nano Banana Pro, powered by Gemini 3, delivers stunning 4K images with perfect text rendering and deep control over lighting and objects. Now available via API/services.
⤷ Title: Palo Alto CEO Warns of Quantum Computing Risk by 2029; Launches Enterprise Browser
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:09:18 +0000
════════════════════════
⌗ Tags: #Information Security #Acquisition #AI Risk #Chronosphere #Cybersecurity Forecast #Enterprise Browser #Palo Alto Networks #Post_Quantum Cryptography #Quantum Computing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:09:18 +0000
════════════════════════
⌗ Tags: #Information Security #Acquisition #AI Risk #Chronosphere #Cybersecurity Forecast #Enterprise Browser #Palo Alto Networks #Post_Quantum Cryptography #Quantum Computing
Penetration Testing Tools
Palo Alto CEO Warns of Quantum Computing Risk by 2029; Launches Enterprise Browser
Palo Alto CEO Nikesh Arora forecasts quantum systems cracking crypto by 2029. The company is preparing solutions, launching a secure browser, and acquired Chronosphere for $3.5B.
⤷ Title: Cl0p Zero-Day Hits Oracle E-Business Suite (CVE-2025-61882), Compromising Global Giants
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:01:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cl0p #CVE_2025_61882 #data breach #E_Business Suite #oracle #ransomware #RCE #supply chain attack #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:01:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cl0p #CVE_2025_61882 #data breach #E_Business Suite #oracle #ransomware #RCE #supply chain attack #zero_day
Penetration Testing Tools
Cl0p Zero-Day Hits Oracle E-Business Suite (CVE-2025-61882), Compromising Global Giants
The Cl0p group exploited a zero-day RCE flaw (CVE-2025-61882) in Oracle E-Business Suite since July, leading to the compromise of major organizations like the NHS and Harvard.
⤷ Title: APT24 Used ‘BadAudio’ Malware in 3-Year Espionage Campaign Hitting 1,000+ Sites
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:59:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BadAudio #China Hacking #Cyber Espionage #DLL hijacking #Google Threat Intelligence #supply chain attack #Watering Hole
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:59:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BadAudio #China Hacking #Cyber Espionage #DLL hijacking #Google Threat Intelligence #supply chain attack #Watering Hole
Penetration Testing Tools
APT24 Used 'BadAudio' Malware in 3-Year Espionage Campaign Hitting 1,000+ Sites
Google uncovered a 3-year APT24 espionage campaign using BadAudio, a stealthy malware delivered via supply chain attacks and fake Windows updates to collect data.
⤷ Title: Samourai Wallet Founders Sentenced to Prison for Laundering $237 Million in Crypto
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:56:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Mixer #Darknet #Money Laundering #Ricochet #Samourai Wallet #Sentencing #US Department of Justice #Whirlpool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:56:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Mixer #Darknet #Money Laundering #Ricochet #Samourai Wallet #Sentencing #US Department of Justice #Whirlpool
Penetration Testing Tools
Samourai Wallet Founders Sentenced to Prison for Laundering $237 Million in Crypto
Samourai Wallet founders were sentenced to 4 and 5 years in prison for running an unlicensed business that laundered $237M in crypto proceeds from darknet crimes.