⤷ Title: Google Unveils Nano Banana Pro: 4K AI Images, Perfect Text, and Gemini 3 Core
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:10:22 +0000
════════════════════════
⌗ Tags: #Google #4K Resolution #AI Image Generation #Controllability #Gemini 3 #Generative AI #google #Nano Banana Pro #Text Rendering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:10:22 +0000
════════════════════════
⌗ Tags: #Google #4K Resolution #AI Image Generation #Controllability #Gemini 3 #Generative AI #google #Nano Banana Pro #Text Rendering
Penetration Testing Tools
Google Unveils Nano Banana Pro: 4K AI Images, Perfect Text, and Gemini 3 Core
Google's Nano Banana Pro, powered by Gemini 3, delivers stunning 4K images with perfect text rendering and deep control over lighting and objects. Now available via API/services.
⤷ Title: Palo Alto CEO Warns of Quantum Computing Risk by 2029; Launches Enterprise Browser
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:09:18 +0000
════════════════════════
⌗ Tags: #Information Security #Acquisition #AI Risk #Chronosphere #Cybersecurity Forecast #Enterprise Browser #Palo Alto Networks #Post_Quantum Cryptography #Quantum Computing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:09:18 +0000
════════════════════════
⌗ Tags: #Information Security #Acquisition #AI Risk #Chronosphere #Cybersecurity Forecast #Enterprise Browser #Palo Alto Networks #Post_Quantum Cryptography #Quantum Computing
Penetration Testing Tools
Palo Alto CEO Warns of Quantum Computing Risk by 2029; Launches Enterprise Browser
Palo Alto CEO Nikesh Arora forecasts quantum systems cracking crypto by 2029. The company is preparing solutions, launching a secure browser, and acquired Chronosphere for $3.5B.
⤷ Title: Cl0p Zero-Day Hits Oracle E-Business Suite (CVE-2025-61882), Compromising Global Giants
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:01:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cl0p #CVE_2025_61882 #data breach #E_Business Suite #oracle #ransomware #RCE #supply chain attack #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:01:28 +0000
════════════════════════
⌗ Tags: #Vulnerability #Cl0p #CVE_2025_61882 #data breach #E_Business Suite #oracle #ransomware #RCE #supply chain attack #zero_day
Penetration Testing Tools
Cl0p Zero-Day Hits Oracle E-Business Suite (CVE-2025-61882), Compromising Global Giants
The Cl0p group exploited a zero-day RCE flaw (CVE-2025-61882) in Oracle E-Business Suite since July, leading to the compromise of major organizations like the NHS and Harvard.
⤷ Title: APT24 Used ‘BadAudio’ Malware in 3-Year Espionage Campaign Hitting 1,000+ Sites
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:59:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BadAudio #China Hacking #Cyber Espionage #DLL hijacking #Google Threat Intelligence #supply chain attack #Watering Hole
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:59:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BadAudio #China Hacking #Cyber Espionage #DLL hijacking #Google Threat Intelligence #supply chain attack #Watering Hole
Penetration Testing Tools
APT24 Used 'BadAudio' Malware in 3-Year Espionage Campaign Hitting 1,000+ Sites
Google uncovered a 3-year APT24 espionage campaign using BadAudio, a stealthy malware delivered via supply chain attacks and fake Windows updates to collect data.
⤷ Title: Samourai Wallet Founders Sentenced to Prison for Laundering $237 Million in Crypto
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:56:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Mixer #Darknet #Money Laundering #Ricochet #Samourai Wallet #Sentencing #US Department of Justice #Whirlpool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:56:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto Mixer #Darknet #Money Laundering #Ricochet #Samourai Wallet #Sentencing #US Department of Justice #Whirlpool
Penetration Testing Tools
Samourai Wallet Founders Sentenced to Prison for Laundering $237 Million in Crypto
Samourai Wallet founders were sentenced to 4 and 5 years in prison for running an unlicensed business that laundered $237M in crypto proceeds from darknet crimes.
⤷ Title: X Opens Username Marketplace to Premium+ Users: Rare Handles Cost Millions?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:35:39 +0000
════════════════════════
⌗ Tags: #Technology #Digital Asset #Elon Musk #Handle Reclamation #monetization #Premium+ Subscription #Social Media #twitter #Usernames #X
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:35:39 +0000
════════════════════════
⌗ Tags: #Technology #Digital Asset #Elon Musk #Handle Reclamation #monetization #Premium+ Subscription #Social Media #twitter #Usernames #X
Daily CyberSecurity
X Opens Username Marketplace to Premium+ Users: Rare Handles Cost Millions?
X is now letting Premium+ subscribers request dormant usernames, dividing them into 'Priority' and 'Rare' categories with ambiguous rules and rumored costs up to millions.
⤷ Title: Google Denies Rumors: Gmail Messages NOT Used to Train Gemini AI Models
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:31:04 +0000
════════════════════════
⌗ Tags: #Technology #AI training #Data Privacy #Gemini #gmail #google #Misleading Reports #Privacy Policy #Smart Features
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:31:04 +0000
════════════════════════
⌗ Tags: #Technology #AI training #Data Privacy #Gemini #gmail #google #Misleading Reports #Privacy Policy #Smart Features
Daily CyberSecurity
Google Denies Rumors: Gmail Messages NOT Used to Train Gemini AI Models
Google firmly denied misleading rumors that it changed its policy to use Gmail content for training Gemini AI models, stressing private data is not used for AI.
⤷ Title: Meta Shifts Real Name Policy: Facebook Groups Now Allow Custom Nicknames & Avatars
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:26:35 +0000
════════════════════════
⌗ Tags: #Technology #Avatars #Community Standards #Facebook Groups #Group Admin #Meta #Nicknames #Privacy Policy #Semi_Anonymity
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:26:35 +0000
════════════════════════
⌗ Tags: #Technology #Avatars #Community Standards #Facebook Groups #Group Admin #Meta #Nicknames #Privacy Policy #Semi_Anonymity
Daily CyberSecurity
Meta Shifts Real Name Policy: Facebook Groups Now Allow Custom Nicknames & Avatars
Meta is relaxing its real-name policy! Facebook Group admins can now allow members to use custom nicknames and dedicated avatars for semi-anonymous discussions.
⤷ Title: Google Testing ‘Sponsored’ Ads Inside Gemini AI Search Results
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:23:43 +0000
════════════════════════
⌗ Tags: #Technology #advertising #AI Search #Enshittification #Gemini #google #monetization #OpenAI #sponsored content #Tech News
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 02:23:43 +0000
════════════════════════
⌗ Tags: #Technology #advertising #AI Search #Enshittification #Gemini #google #monetization #OpenAI #sponsored content #Tech News
Daily CyberSecurity
Google Testing 'Sponsored' Ads Inside Gemini AI Search Results
Google is testing sponsored links within Gemini's "AI Mode" search results. The ads are visually subtle, signaling the inevitable monetization of AI-powered search.
⤷ Title: Critical 7 Zip Vulnerability With Public Exploit Requires Manual Update
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 12:48:05 +0000
════════════════════════
⌗ Tags: #Malware #Security #7_Zip #Cybersecurity #Microsoft #Vulnerability #Windows
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 12:48:05 +0000
════════════════════════
⌗ Tags: #Malware #Security #7_Zip #Cybersecurity #Microsoft #Vulnerability #Windows
Hackread
Critical 7 Zip Vulnerability With Public Exploit Requires Manual Update
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Code Injection Flaws Threaten NVIDIA’s Isaac-GROOT Robotics Platform
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 01:52:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2025_33183 #CVE_2025_33184 #cybersecurity #High Severity #Isaac_GROOT #nvidia #Python vulnerability #Robotics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 01:52:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #code_injection #CVE_2025_33183 #CVE_2025_33184 #cybersecurity #High Severity #Isaac_GROOT #nvidia #Python vulnerability #Robotics
Daily CyberSecurity
Code Injection Flaws Threaten NVIDIA's Isaac-GROOT Robotics Platform
NVIDIA patches two high-severity code injection flaws (CVE-2025-33183/4) in Isaac-GROOT, risking code execution & privilege escalation in robotics.
⤷ Title: TamperedChef Malvertising Uses US Shell Companies to Sign Trojanized Apps with Valid Certificates, Deploying Stealth Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:42:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Code_Signing Certificate #JavaScript Backdoor #Malvertising #Scheduled Task #SEO Poisoning #Signed Trojan #TamperedChef
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:42:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Code_Signing Certificate #JavaScript Backdoor #Malvertising #Scheduled Task #SEO Poisoning #Signed Trojan #TamperedChef
Daily CyberSecurity
TamperedChef Malvertising Uses US Shell Companies to Sign Trojanized Apps with Valid Certificates, Deploying Stealth Backdoor
Acronis exposed TamperedChef, a global campaign using US shell companies to sign trojanized apps. The malware deploys a stealthy, obfuscated JavaScript backdoor via a scheduled task for long-term persistence.
⤷ Title: vLLM Flaw (CVE-2025-62164) Risks Remote Code Execution via Malicious Prompt Embeddings
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Inference #Critical Vulnerability #Embeddings #LLM Security #memory corruption #PyTorch #rce #vLLM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Inference #Critical Vulnerability #Embeddings #LLM Security #memory corruption #PyTorch #rce #vLLM
Daily CyberSecurity
vLLM Flaw (CVE-2025-62164) Risks Remote Code Execution via Malicious Prompt Embeddings
A RCE flaw (CVE-2025-62164) in the vLLM inference engine allows attackers to crash servers or execute code by exploiting an out-of-bounds memory write via malicious prompt embeddings.
⤷ Title: China’s APT24 Launches Stealth BADAUDIO Malware, Hitting 1,000+ Domains via Taiwanese Supply Chain Hack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:36:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BADAUDIO #China APT #Control Flow Flattening #cyber_espionage #supply chain attack #Taiwan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:36:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BADAUDIO #China APT #Control Flow Flattening #cyber_espionage #supply chain attack #Taiwan
Daily CyberSecurity
China’s APT24 Launches Stealth BADAUDIO Malware, Hitting 1,000+ Domains via Taiwanese Supply Chain Hack
Google exposed APT24's stealth BADAUDIO C++ downloader. The three-year campaign includes a supply chain hack hitting 1,000+ domains, using control flow flattening and AES-encrypted cookies for C2.
⤷ Title: Sophisticated WhatsApp Worm Uses Fake “View Once” Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
Daily CyberSecurity
Sophisticated WhatsApp Worm Uses Fake "View Once" Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
Sophos exposed STAC3150, a campaign using fake "View Once" messages to deploy Astaroth banking trojan. The malware hijacks WhatsApp Web sessions via WPPConnect/Selenium for self-propagation.
⤷ Title: CERT/CC Warns of Unpatched Root-Level Command Injection Flaws in Tenda 4G03 Pro and N300 Routers (CVE-2025-13207, CVE-2024-24481)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #Command Injection #CVE_2025_13207 #rce #root access #Tenda Router #Unpatched Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #Command Injection #CVE_2025_13207 #rce #root access #Tenda Router #Unpatched Vulnerability
Daily CyberSecurity
CERT/CC Warns of Unpatched Root-Level Command Injection Flaws in Tenda 4G03 Pro and N300 Routers (CVE-2025-13207, CVE-2024-24481)
CERT/CC warned that Tenda 4G03 Pro/N300 routers are exposed to an unpatched RCE flaw (CVE-2025-13207). Authenticated attackers can execute root-level commands via web requests due to insecure input handling.
⤷ Title: Next-Gen Threat: Xillen Stealer v4 Targets 100+ Browsers/70+ Wallets with Polymorphic Evasion and DevOps Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Malware #AI Evasion #Darktrace #Kubernetes Secrets #Polymorphic Engine #Rust malware #steganography #Xillen Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Malware #AI Evasion #Darktrace #Kubernetes Secrets #Polymorphic Engine #Rust malware #steganography #Xillen Stealer
Daily CyberSecurity
Next-Gen Threat: Xillen Stealer v4 Targets 100+ Browsers/70+ Wallets with Polymorphic Evasion and DevOps Theft
Darktrace exposed Xillen Stealer v4/v5, a new MaaS threat using Rust polymorphism and an AIEvasionEngine to target 100+ browsers and Kubernetes/DevOps secrets. It uses steganography for exfiltration.
⤷ Title: Critical ABB Flaw (CVE-2025-10571, CVSS 9.6) Allows Unauthenticated RCE and Admin Takeover on Edgenius
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:22:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB Edgenius #Authentication Bypass #Critical Vulnerability #CVE_2025_10571 #OT Security #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:22:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB Edgenius #Authentication Bypass #Critical Vulnerability #CVE_2025_10571 #OT Security #rce
Daily CyberSecurity
Critical ABB Flaw (CVE-2025-10571, CVSS 9.6) Allows Unauthenticated RCE and Admin Takeover on Edgenius
ABB patched a Critical (CVSS 9.6) Auth Bypass flaw (CVE-2025-10571) in Edgenius Management Portal. The bug allows unauthenticated remote attackers to install apps and execute arbitrary code. Update to v3.2.2.0.
⤷ Title: Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:19:48 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #Cybercrime Marketplace #Ethereum Smart Contract #kaspersky #MSI Installer #Node.js Botnet #Tsundere
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:19:48 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #Cybercrime Marketplace #Ethereum Smart Contract #kaspersky #MSI Installer #Node.js Botnet #Tsundere
Daily CyberSecurity
Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace
Kaspersky exposed Tsundere, a Node.js botnet using an Ethereum smart contract for unkillable C2 updates. The system includes a cybercrime marketplace and spreads via fake MSI game installers for RCE.
⤷ Title: PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
Daily CyberSecurity
PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
A malicious PyPI typosquat (spellcheckers) infected 950+ users. The package deploys an XOR-encrypted Python RAT via a hidden index file, granting full remote execution (exec()) and is linked to crypto scams.
⤷ Title: Critical Markdown to PDF Flaw (CVE-2025-65108, CVSS 10.0) Allows RCE via JS Injection in Markdown Front-Matter
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:11:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65108 #gray_matter #Markdown #md_to_pdf #rce #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:11:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65108 #gray_matter #Markdown #md_to_pdf #rce #Supply Chain
Daily CyberSecurity
Critical Markdown to PDF Flaw (CVE-2025-65108, CVSS 10.0) Allows RCE via JS Injection in Markdown Front-Matter
A Critical (CVSS 10.0) RCE flaw (CVE-2025-65108) in md-to-pdf allows arbitrary JavaScript code execution via malicious front-matter. Over 47K weekly downloads are affected. Update to v5.2.5.