⤷ Title: China-Nexus Autumn Dragon APT Exploits WinRAR Flaw to Deploy Telegram C2 Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:00:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Autumn Dragon #China APT #cyber_espionage #DLL Sideloading #Southeast Asia #Telegram C2 #WinRAR Exploit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:00:28 +0000
════════════════════════
⌗ Tags: #Cyber Security #Autumn Dragon #China APT #cyber_espionage #DLL Sideloading #Southeast Asia #Telegram C2 #WinRAR Exploit
Daily CyberSecurity
China-Nexus Autumn Dragon APT Exploits WinRAR Flaw to Deploy Telegram C2 Backdoor
CyberArmor exposed Autumn Dragon, a China-nexus APT using a WinRAR path traversal flaw (CVE-2025-8088) and DLL sideloading to deploy a Telegram C2 backdoor for espionage in Southeast Asia.
⤷ Title: Critical WordPress Flaw (CVE-2025-6389, CVSS 9.8) Under Active Exploitation Allows Unauthenticated RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 01:59:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical RCE #CVE_2025_6389 #FlatNews #Sneeit Framework #unauthenticated RCE #Web Security #wordpress
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 01:59:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical RCE #CVE_2025_6389 #FlatNews #Sneeit Framework #unauthenticated RCE #Web Security #wordpress
Daily CyberSecurity
Critical WordPress Flaw (CVE-2025-6389, CVSS 9.8) Under Active Exploitation Allows Unauthenticated RCE
A Critical (CVSS 9.8) RCE flaw in Sneeit Framework is actively exploited. The bug allows unauthenticated attackers to run arbitrary code via call_user_func and take over WordPress sites. Update to v8.4 immediately.
⤷ Title: High-Severity Vault Flaw (CVE-2025-13357) Allows Unauthenticated Access via LDAP Null Bind Insecure Default
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:36:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13357 #HashiCorp Vault #Insecure Default #LDAP #Terraform Provider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:36:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13357 #HashiCorp Vault #Insecure Default #LDAP #Terraform Provider
Daily CyberSecurity
High-Severity Vault Flaw (CVE-2025-13357) Allows Unauthenticated Access via LDAP Null Bind Insecure Default
A High-severity flaw (CVE-2025-13357, CVSS 7.4) in the Vault Terraform Provider allows unauthenticated access via LDAP null binds due to an insecure deny_null_bind default setting. Update to v5.5.0.
⤷ Title: Critical Unpatched Flaw: Vivotek EOL IP Cameras Exposed to Unauthenticated RCE via Command Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:31:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2019_19936 #end_of_life #IoT security #IP Camera #rce #unauthenticated access #Vivotek
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:31:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2019_19936 #end_of_life #IoT security #IP Camera #rce #unauthenticated access #Vivotek
Daily CyberSecurity
Critical Unpatched Flaw: Vivotek EOL IP Cameras Exposed to Unauthenticated RCE via Command Injection
A critical, unpatched flaw in EOL Vivotek IP Cameras allows unauthenticated RCE via command injection in eventtask.cgi. Firmware versions 0100c–0305a4 are vulnerable and will not receive fixes.
⤷ Title: CVE-2025-63207 (CVSS 9.8): Critical Broken Access Control Flaw Exposes R.V.R Elettronica TEX Devices to Full System Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:25:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Broadcast Hardware #Critical Vulnerability #CVE_2025_63207 #password reset #R.V.R Elettronica
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:25:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Broadcast Hardware #Critical Vulnerability #CVE_2025_63207 #password reset #R.V.R Elettronica
Daily CyberSecurity
CVE-2025-63207 (CVSS 9.8): Critical Broken Access Control Flaw Exposes R.V.R Elettronica TEX Devices to Full System Takeover
A Critical (CVSS 9.8) Auth Bypass flaw (CVE-2025-63207) in R.V.R Elettronica TEX broadcast hardware allows unauthenticated attackers to reset all user passwords (Admin/Operator) via a simple HTTP request.
⤷ Title: ToddyCat APT Steals Microsoft 365 Cloud Email by Dumping OAuth Tokens from Memory and Copying Locked OST Files
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:21:05 +0000
════════════════════════
⌗ Tags: #Malware #APT #cyber_espionage #Microsoft 365 #OAuth Token Theft #Outlook OST #ProcDump #TCSectorCopy #ToddyCat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:21:05 +0000
════════════════════════
⌗ Tags: #Malware #APT #cyber_espionage #Microsoft 365 #OAuth Token Theft #Outlook OST #ProcDump #TCSectorCopy #ToddyCat
Daily CyberSecurity
ToddyCat APT Steals Microsoft 365 Cloud Email by Dumping OAuth Tokens from Memory and Copying Locked OST Files
Kaspersky exposed ToddyCat APT's evolution: the group steals M365 OAuth tokens from memory and uses TCSectorCopy to steal locked Outlook OST files, allowing covert access to cloud email outside the perimeter.
⤷ Title: Kimsuky APT Deploys Dual KimJongRAT Payloads, Switching Between PE/PowerShell Based on Windows Defender Status
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Malware #DPRK APT #Dual Payload #GitHub Releases #KimJongRAT #Kimsuky #LNK Exploit #Windows Defender Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:16:35 +0000
════════════════════════
⌗ Tags: #Malware #DPRK APT #Dual Payload #GitHub Releases #KimJongRAT #Kimsuky #LNK Exploit #Windows Defender Bypass
Daily CyberSecurity
Kimsuky APT Deploys Dual KimJongRAT Payloads, Switching Between PE/PowerShell Based on Windows Defender Status
ENKI exposed a Kimsuky APT campaign using a dual PE/PowerShell payload that switches based on Windows Defender status to deploy KimJongRAT. The malware steals Chrome AppBound keys via GitHub Releases C2.
⤷ Title: Brazilian Banking Trojan Uses Python WhatsApp Worm and IMAP C2 for In-Memory Credential Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:11:04 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt Loader #Brazilian Banking Trojan #IMAP C2 #In_Memory Injection #Python #WhatsApp Worm #WPPConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:11:04 +0000
════════════════════════
⌗ Tags: #Malware #AutoIt Loader #Brazilian Banking Trojan #IMAP C2 #In_Memory Injection #Python #WhatsApp Worm #WPPConnect
Daily CyberSecurity
Brazilian Banking Trojan Uses Python WhatsApp Worm and IMAP C2 for In-Memory Credential Theft
K7 Labs exposed a Brazilian campaign using a Python WhatsApp worm for self-propagation. The in-memory AutoIt loader deploys a banking trojan that uses IMAP email as a covert C2 channel to steal banking credentials.
⤷ Title: North Korea’s Operation DreamJob Hits Europe: WhatsApp Job Lure Delivers Evolved MISTPEN/BURNBOOK Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:05:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #BURNBOOK #DLL Sideloading #DPRK APT #DreamJob #MISTPEN #Pass_the_hash #UNC2970 #WhatsApp Lure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:05:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #BURNBOOK #DLL Sideloading #DPRK APT #DreamJob #MISTPEN #Pass_the_hash #UNC2970 #WhatsApp Lure
Daily CyberSecurity
North Korea's Operation DreamJob Hits Europe: WhatsApp Job Lure Delivers Evolved MISTPEN/BURNBOOK Backdoors
⤷ Title: ShinyHunters Claims Salesforce Ecosystem Breach via Stolen OAuth Tokens from Gainsight
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:32:39 +0000
════════════════════════
⌗ Tags: #Data Leak #AppExchange #cybercrime #Gainsight #HubSpot #OAuth Tokens #Salesforce #Salesforce Gainsight Breach #ShinyHunters #supply chain attack #Zendesk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:32:39 +0000
════════════════════════
⌗ Tags: #Data Leak #AppExchange #cybercrime #Gainsight #HubSpot #OAuth Tokens #Salesforce #Salesforce Gainsight Breach #ShinyHunters #supply chain attack #Zendesk
Penetration Testing Tools
ShinyHunters Claims Salesforce Ecosystem Breach via Stolen OAuth Tokens from Gainsight
ShinyHunters claims responsibility for the Salesforce ecosystem breach, using OAuth tokens stolen from a previous attack to infiltrate Gainsight and access hundreds of customer instances.
⤷ Title: Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:30:12 +0000
════════════════════════
⌗ Tags: #Vulnerability #AhnLab #China APT #CVE_2025_59287 #Cyber Espionage #Patch Now #RCE #ShadowPad #Windows Server #WSUS
Penetration Testing Tools
Critical WSUS RCE (CVE-2025-59287) Actively Exploited to Deploy ShadowPad Espionage Tool
Threat actors are actively exploiting the critical WSUS RCE flaw (CVE-2025-59287) to gain SYSTEM access and deploy the powerful, Chinese-linked ShadowPad espionage backdoor.
⤷ Title: Matrix Push C2: New Subscription Service Fuels Fileless Browser Push Notification Phishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:28:53 +0000
════════════════════════
⌗ Tags: #Malware #BlackFog #Browser Hijacking #Cybercrime Service #Fileless Attack #Matrix Push C2 #phishing #Push Notifications #Social Engineering
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:28:53 +0000
════════════════════════
⌗ Tags: #Malware #BlackFog #Browser Hijacking #Cybercrime Service #Fileless Attack #Matrix Push C2 #phishing #Push Notifications #Social Engineering
Penetration Testing Tools
Matrix Push C2: New Subscription Service Fuels Fileless Browser Push Notification Phishing
Matrix Push C2 is a new subscription service fueling fileless phishing campaigns by using deceptive browser push notifications to deliver malicious links and steal credentials.
⤷ Title: Mortgage Market Crisis: SitusAMC Breach Exposes Data for Customers of JPMorgan, Citi
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:27:51 +0000
════════════════════════
⌗ Tags: #Data Leak #Citi #cybersecurity #data breach #Financial Services #JPMorgan Chase #Mortgage Market #SitusAMC #third_party risk
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:27:51 +0000
════════════════════════
⌗ Tags: #Data Leak #Citi #cybersecurity #data breach #Financial Services #JPMorgan Chase #Mortgage Market #SitusAMC #third_party risk
Penetration Testing Tools
Mortgage Market Crisis: SitusAMC Breach Exposes Data for Customers of JPMorgan, Citi
SitusAMC, a key mortgage market contractor, suffered a breach that may have exposed client data from major banks like JPMorgan and Citi, raising fears of supply chain risk.
⤷ Title: NVIDIA 1.6 Tbps Networking Arrives in Linux 6.19 Kernel via Mellanox MLX5
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:17:20 +0000
════════════════════════
⌗ Tags: #Linux #1.6 Tbps #AI Workloads #data center #Linux Kernel 6.19 #Mellanox #MLX5 #Networking #Nvidia #RDMA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:17:20 +0000
════════════════════════
⌗ Tags: #Linux #1.6 Tbps #AI Workloads #data center #Linux Kernel 6.19 #Mellanox #MLX5 #Networking #Nvidia #RDMA
Penetration Testing Tools
NVIDIA 1.6 Tbps Networking Arrives in Linux 6.19 Kernel via Mellanox MLX5
NVIDIA is adding 1.6 Tbps networking support to the Linux 6.19 kernel via the Mellanox MLX5 driver, utilizing eight 200 Gbps lanes for next-gen data center speed.
⤷ Title: CRITICAL: Fluent Bit Flaws Enable RCE and Telemetry Tampering in Major Orgs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:07:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_12972 #Fluent Bit #Kubernetes Security #Log Tampering #Oligo Security #Remote Code Execution #Telemetry Agent
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 03:07:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2025_12972 #Fluent Bit #Kubernetes Security #Log Tampering #Oligo Security #Remote Code Execution #Telemetry Agent
Daily CyberSecurity
CRITICAL: Fluent Bit Flaws Enable RCE and Telemetry Tampering in Major Orgs
A critical chain of Fluent Bit vulnerabilities allows RCE, path traversal, and log tampering by exploiting tag handling and an auth bypass. Update to v4.1.1 now.
⤷ Title: Apache Syncope Flaw (CVE-2025-65998) Exposes Encrypted User Passwords Due to Hard-Coded AES Key
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 02:52:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Syncope #Critical Flaw #CVE_2025_65998 #Hard_Coded Key #Identity Management #Password Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 02:52:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Syncope #Critical Flaw #CVE_2025_65998 #Hard_Coded Key #Identity Management #Password Encryption
Daily CyberSecurity
Apache Syncope Flaw (CVE-2025-65998) Exposes Encrypted User Passwords Due to Hard-Coded AES Key
Apache warned of a Critical flaw (CVE-2025-65998) in Syncope. When AES is enabled for password storage, a hard-coded key allows attackers with database access to decrypt all user passwords. Update immediately.
⤷ Title: CISA Emergency Alert: Commercial Spyware Exploiting Zero-Click and Malicious QR Codes to Hijack Messaging Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 02:42:03 +0000
════════════════════════
⌗ Tags: #Malware #CISA #commercial spyware #messaging app #Pegasus #QR code phishing #Signal #WhatsApp #Zero_Click
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 02:42:03 +0000
════════════════════════
⌗ Tags: #Malware #CISA #commercial spyware #messaging app #Pegasus #QR code phishing #Signal #WhatsApp #Zero_Click
Daily CyberSecurity
CISA Emergency Alert: Commercial Spyware Exploiting Zero-Click and Malicious QR Codes to Hijack Messaging Apps
CISA issued an urgent alert: Commercial spyware is actively exploiting zero-click flaws and malicious QR codes to hijack messaging apps (Signal, WhatsApp) for espionage against government and civil society targets.
⤷ Title: CISA Warns of Active Spyware Campaigns Hijacking High-Value Signal and WhatsApp Users
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 12:12:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 12:12:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Golden dMSA: tool exploits Golden DMSA attack against delegated Managed Service Accounts.
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 08:48:06 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Golden dMSA #Golden DMSA attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 08:48:06 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Golden dMSA #Golden DMSA attack
Penetration Testing Tools
Golden dMSA: tool exploits Golden DMSA attack against delegated Managed Service Accounts.
Golden dMSA tool exploits Golden DMSA attack against delegated Managed Service Accounts.
⤷ Title: Understanding signal-to-noise for vulnerability management success
════════════════════════
𐀪 Author: Eleanor Barlow
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Business Insights
════════════════════════
𐀪 Author: Eleanor Barlow
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:00:00 GMT
════════════════════════
⌗ Tags: #Business Insights
Intigriti
Understanding signal-to-noise for vulnerability management success
Turn your signal-to-noise ratio into a key metric, learn how to score it, and identify challenges regarding scope, policy, staff, rewards, researchers, and processes.
⤷ Title: 3 SOC Challenges You Need to Solve Before 2026
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 17:00:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 17:00:00 +0530
════════════════════════
⌗ Tags: No_Tags