⤷ Title: TamperedChef Malvertising Uses US Shell Companies to Sign Trojanized Apps with Valid Certificates, Deploying Stealth Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:42:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Code_Signing Certificate #JavaScript Backdoor #Malvertising #Scheduled Task #SEO Poisoning #Signed Trojan #TamperedChef
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:42:28 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Acronis #Code_Signing Certificate #JavaScript Backdoor #Malvertising #Scheduled Task #SEO Poisoning #Signed Trojan #TamperedChef
Daily CyberSecurity
TamperedChef Malvertising Uses US Shell Companies to Sign Trojanized Apps with Valid Certificates, Deploying Stealth Backdoor
Acronis exposed TamperedChef, a global campaign using US shell companies to sign trojanized apps. The malware deploys a stealthy, obfuscated JavaScript backdoor via a scheduled task for long-term persistence.
⤷ Title: vLLM Flaw (CVE-2025-62164) Risks Remote Code Execution via Malicious Prompt Embeddings
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Inference #Critical Vulnerability #Embeddings #LLM Security #memory corruption #PyTorch #rce #vLLM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Inference #Critical Vulnerability #Embeddings #LLM Security #memory corruption #PyTorch #rce #vLLM
Daily CyberSecurity
vLLM Flaw (CVE-2025-62164) Risks Remote Code Execution via Malicious Prompt Embeddings
A RCE flaw (CVE-2025-62164) in the vLLM inference engine allows attackers to crash servers or execute code by exploiting an out-of-bounds memory write via malicious prompt embeddings.
⤷ Title: China’s APT24 Launches Stealth BADAUDIO Malware, Hitting 1,000+ Domains via Taiwanese Supply Chain Hack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:36:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BADAUDIO #China APT #Control Flow Flattening #cyber_espionage #supply chain attack #Taiwan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:36:57 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT24 #BADAUDIO #China APT #Control Flow Flattening #cyber_espionage #supply chain attack #Taiwan
Daily CyberSecurity
China’s APT24 Launches Stealth BADAUDIO Malware, Hitting 1,000+ Domains via Taiwanese Supply Chain Hack
Google exposed APT24's stealth BADAUDIO C++ downloader. The three-year campaign includes a supply chain hack hitting 1,000+ domains, using control flow flattening and AES-encrypted cookies for C2.
⤷ Title: Sophisticated WhatsApp Worm Uses Fake “View Once” Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:33:37 +0000
════════════════════════
⌗ Tags: #Malware #Astaroth #Banking Trojan #Selenium #Session Hijacking #STAC3150 #VBScript #WhatsApp #WPPConnect
Daily CyberSecurity
Sophisticated WhatsApp Worm Uses Fake "View Once" Lure to Hijack Sessions and Deploy Astaroth Banking Trojan
Sophos exposed STAC3150, a campaign using fake "View Once" messages to deploy Astaroth banking trojan. The malware hijacks WhatsApp Web sessions via WPPConnect/Selenium for self-propagation.
⤷ Title: CERT/CC Warns of Unpatched Root-Level Command Injection Flaws in Tenda 4G03 Pro and N300 Routers (CVE-2025-13207, CVE-2024-24481)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #Command Injection #CVE_2025_13207 #rce #root access #Tenda Router #Unpatched Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:29:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CERT/CC #Command Injection #CVE_2025_13207 #rce #root access #Tenda Router #Unpatched Vulnerability
Daily CyberSecurity
CERT/CC Warns of Unpatched Root-Level Command Injection Flaws in Tenda 4G03 Pro and N300 Routers (CVE-2025-13207, CVE-2024-24481)
CERT/CC warned that Tenda 4G03 Pro/N300 routers are exposed to an unpatched RCE flaw (CVE-2025-13207). Authenticated attackers can execute root-level commands via web requests due to insecure input handling.
⤷ Title: Next-Gen Threat: Xillen Stealer v4 Targets 100+ Browsers/70+ Wallets with Polymorphic Evasion and DevOps Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Malware #AI Evasion #Darktrace #Kubernetes Secrets #Polymorphic Engine #Rust malware #steganography #Xillen Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:26:25 +0000
════════════════════════
⌗ Tags: #Malware #AI Evasion #Darktrace #Kubernetes Secrets #Polymorphic Engine #Rust malware #steganography #Xillen Stealer
Daily CyberSecurity
Next-Gen Threat: Xillen Stealer v4 Targets 100+ Browsers/70+ Wallets with Polymorphic Evasion and DevOps Theft
Darktrace exposed Xillen Stealer v4/v5, a new MaaS threat using Rust polymorphism and an AIEvasionEngine to target 100+ browsers and Kubernetes/DevOps secrets. It uses steganography for exfiltration.
⤷ Title: Critical ABB Flaw (CVE-2025-10571, CVSS 9.6) Allows Unauthenticated RCE and Admin Takeover on Edgenius
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:22:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB Edgenius #Authentication Bypass #Critical Vulnerability #CVE_2025_10571 #OT Security #rce
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:22:30 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ABB Edgenius #Authentication Bypass #Critical Vulnerability #CVE_2025_10571 #OT Security #rce
Daily CyberSecurity
Critical ABB Flaw (CVE-2025-10571, CVSS 9.6) Allows Unauthenticated RCE and Admin Takeover on Edgenius
ABB patched a Critical (CVSS 9.6) Auth Bypass flaw (CVE-2025-10571) in Edgenius Management Portal. The bug allows unauthenticated remote attackers to install apps and execute arbitrary code. Update to v3.2.2.0.
⤷ Title: Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:19:48 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #Cybercrime Marketplace #Ethereum Smart Contract #kaspersky #MSI Installer #Node.js Botnet #Tsundere
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:19:48 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain C2 #Cybercrime Marketplace #Ethereum Smart Contract #kaspersky #MSI Installer #Node.js Botnet #Tsundere
Daily CyberSecurity
Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace
Kaspersky exposed Tsundere, a Node.js botnet using an Ethereum smart contract for unkillable C2 updates. The system includes a cybercrime marketplace and spreads via fake MSI game installers for RCE.
⤷ Title: PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
Daily CyberSecurity
PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
A malicious PyPI typosquat (spellcheckers) infected 950+ users. The package deploys an XOR-encrypted Python RAT via a hidden index file, granting full remote execution (exec()) and is linked to crypto scams.
⤷ Title: Critical Markdown to PDF Flaw (CVE-2025-65108, CVSS 10.0) Allows RCE via JS Injection in Markdown Front-Matter
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:11:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65108 #gray_matter #Markdown #md_to_pdf #rce #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:11:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65108 #gray_matter #Markdown #md_to_pdf #rce #Supply Chain
Daily CyberSecurity
Critical Markdown to PDF Flaw (CVE-2025-65108, CVSS 10.0) Allows RCE via JS Injection in Markdown Front-Matter
A Critical (CVSS 10.0) RCE flaw (CVE-2025-65108) in md-to-pdf allows arbitrary JavaScript code execution via malicious front-matter. Over 47K weekly downloads are affected. Update to v5.2.5.
⤷ Title: Eternidade Stealer: New Python WhatsApp Worm Uses IMAP Email for Covert C2 and Brazilian Bank Overlays
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:05:47 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Eternidade Stealer #IMAP C2 #Python #Trustwave #WhatsApp Worm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:05:47 +0000
════════════════════════
⌗ Tags: #Malware #Banking Trojan #Brazil #Eternidade Stealer #IMAP C2 #Python #Trustwave #WhatsApp Worm
Daily CyberSecurity
Eternidade Stealer: New Python WhatsApp Worm Uses IMAP Email for Covert C2 and Brazilian Bank Overlays
Trustwave exposed Eternidade Stealer, a sophisticated Brazilian Trojan. The Python WhatsApp worm steals contact lists and uses IMAP email for covert C2 retrieval to launch banking overlays.
⤷ Title: Extreme Stealth: Python Malware Hides Inside PNG-Disguised RAR, Injects Payload into cvtres.exe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:01:01 +0000
════════════════════════
⌗ Tags: #Malware #cvtres.exe #Multi_Layer Encoding #Obfuscation #Process injection #Python Malware #RAR Archive #steganography
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:01:01 +0000
════════════════════════
⌗ Tags: #Malware #cvtres.exe #Multi_Layer Encoding #Obfuscation #Process injection #Python Malware #RAR Archive #steganography
Daily CyberSecurity
Extreme Stealth: Python Malware Hides Inside PNG-Disguised RAR, Injects Payload into cvtres.exe
K7 Labs exposed a Python malware using multi-layer encoding (Base64/BZ2/Zlib) and a PNG-disguised RAR archive. The payload executes in memory and achieves stealth by injecting into cvtres.exe.
⤷ Title: Wscan: New Open-Source Web Scanner Uses ML for Automated, Personalized Penetration Testing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:34:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Automation #machine learning #ML #nmap #open source #Penetration Testing #security scanner #web security #Wscan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:34:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Automation #machine learning #ML #nmap #open source #Penetration Testing #security scanner #web security #Wscan
Penetration Testing Tools
Wscan: New Open-Source Web Scanner Uses ML for Automated, Personalized Penetration Testing
Wscan is a new open-source web scanner using Machine Learning for fully automated, personalized penetration testing, aiming for high efficiency, accuracy, and low false positives.
⤷ Title: URGENT Patch: GRUB2 Flaws Allow Secure Boot Bypass via Use-After-Free Exploits
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:30:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bootloader #CVE_2025_61661 #GRUB2 #Linux Security #SBAT #Secure Boot #UEFI #use_after_free
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:30:07 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bootloader #CVE_2025_61661 #GRUB2 #Linux Security #SBAT #Secure Boot #UEFI #use_after_free
Penetration Testing Tools
URGENT Patch: GRUB2 Flaws Allow Secure Boot Bypass via Use-After-Free Exploits
A new GRUB2 patch fixes six critical flaws (like CVE-2025-61661) that could bypass UEFI Secure Boot. Full boot chain rebuild and SBAT support are required.
⤷ Title: UK Dismantles Financial Network Bankrolling Jan Marsalek’s Spy Ring via Crypto
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:28:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #Financial Crime #Jan Marsalek #Money Laundering #NCA #Spy Ring #Tether #UK Security #Wirecard
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:28:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cryptocurrency #Financial Crime #Jan Marsalek #Money Laundering #NCA #Spy Ring #Tether #UK Security #Wirecard
Penetration Testing Tools
UK Dismantles Financial Network Bankrolling Jan Marsalek’s Spy Ring via Crypto
The UK's NCA dismantled the financial network that bankrolled a spy ring linked to Jan Marsalek, exposing a sophisticated crypto-laundering scheme that moved billions.
⤷ Title: Princeton, Harvard Hacked: AI-Augmented Attacks Fuel Surge in University Breaches
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:25:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #AI Attacks #Geopolitical Threat #Harvard #Intellectual Property #Princeton #ransomware #University Hacking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:25:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #AI Attacks #Geopolitical Threat #Harvard #Intellectual Property #Princeton #ransomware #University Hacking
Penetration Testing Tools
Princeton, Harvard Hacked: AI-Augmented Attacks Fuel Surge in University Breaches
Cyberattacks on universities (Princeton, Harvard, UPenn) surge globally. Experts warn that AI-augmented hacking and complex infrastructure make the sector highly vulnerable.
⤷ Title: NSO Group Appeals Pegasus Spyware Ban, Claims Ruling Threatens Company Closure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:19:38 +0000
════════════════════════
⌗ Tags: #Malware #Court Ruling #Cyber Surveillance #Injunction #legal battle #Meta #NSO Group #Pegasus spyware #WhatsApp #Zero_Click
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:19:38 +0000
════════════════════════
⌗ Tags: #Malware #Court Ruling #Cyber Surveillance #Injunction #legal battle #Meta #NSO Group #Pegasus spyware #WhatsApp #Zero_Click
Penetration Testing Tools
NSO Group Appeals Pegasus Spyware Ban, Claims Ruling Threatens Company Closure
NSO Group is appealing a federal injunction banning it from using WhatsApp's infrastructure to deploy Pegasus spyware, arguing the order could force the company to shut down.
⤷ Title: Microsoft Releases Emergency Hotfix KB5072753 to Stop Windows 11 Update Loop
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:17:19 +0000
════════════════════════
⌗ Tags: #Windows #Hotfix #KB5068966 #KB5072753 #Microsoft #Out_of_Band #System Error #Update Loop #Windows 11 #Windows Update
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:17:19 +0000
════════════════════════
⌗ Tags: #Windows #Hotfix #KB5068966 #KB5072753 #Microsoft #Out_of_Band #System Error #Update Loop #Windows 11 #Windows Update
Penetration Testing Tools
Microsoft Releases Emergency Hotfix KB5072753 to Stop Windows 11 Update Loop
Microsoft released out-of-band update KB5072753 for Windows 11 25H2 to fix a bug where the previous KB5068966 hotfix was being repeatedly reinstalled on affected systems.
⤷ Title: NVIDIA Hotfix 581.94 Released to Fix Windows 11 Update Game Performance Drops
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:09:59 +0000
════════════════════════
⌗ Tags: #Technology #Windows #FPS Drop #gaming #GeForce #Hotfix Driver #KB5066835 #Microsoft Update #Nvidia #Performance Degradation #Windows 11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:09:59 +0000
════════════════════════
⌗ Tags: #Technology #Windows #FPS Drop #gaming #GeForce #Hotfix Driver #KB5066835 #Microsoft Update #Nvidia #Performance Degradation #Windows 11
Penetration Testing Tools
NVIDIA Hotfix 581.94 Released to Fix Windows 11 Update Game Performance Drops
NVIDIA released GeForce Hotfix Driver 581.94 to mitigate significant game performance drops (FPS) caused by Microsoft's recent October Windows 11 update KB5066835.
⤷ Title: UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
Penetration Testing Tools
UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
The UNC2891 campaign against Indonesian banks used a Raspberry Pi and the CAKETAP rootkit to bypass ATM verification protocols, orchestrating cash-outs via a mule network.
⤷ Title: Internal Errors Plague Cloud Giants: AWS, Azure, & Cloudflare Hit by Configuration Outages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:06:01 +0000
════════════════════════
⌗ Tags: #Technology #AWS #Cloud Outage #Cloud Resilience #Cloudflare #Configuration Error #DNS Failure #metadata #Microsoft Azure #Single Point of Failure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:06:01 +0000
════════════════════════
⌗ Tags: #Technology #AWS #Cloud Outage #Cloud Resilience #Cloudflare #Configuration Error #DNS Failure #metadata #Microsoft Azure #Single Point of Failure
Penetration Testing Tools
Internal Errors Plague Cloud Giants: AWS, Azure, & Cloudflare Hit by Configuration Outages
Recent outages at AWS, Azure, and Cloudflare show that internal configuration errors, not attacks, are the new single point of failure in hyper-automated global cloud infrastructure.