⤷ Title: Water Gamayun Weaponizes “MSC EvilTwin” Zero-Day for Stealthy Backdoor Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:28:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #CVE_2025_26633 #cyber_espionage #EncryptHub #malware #MSC EvilTwin #Water Gamayun #zero_day #Zscaler
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:28:11 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #CVE_2025_26633 #cyber_espionage #EncryptHub #malware #MSC EvilTwin #Water Gamayun #zero_day #Zscaler
Daily CyberSecurity
Water Gamayun Weaponizes “MSC EvilTwin” Zero-Day for Stealthy Backdoor Attacks
A sophisticated new cyber espionage campaign has been uncovered by Zscaler Threat Hunting, revealing how a Russia-aligned Advanced Persistent Threat (APT) group known as Water Gamayun is weaponizi…
⤷ Title: Fragging Your Data: Fake ‘Battlefield 6’ Cracks & Trainers Spread Infostealers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:22:37 +0000
════════════════════════
⌗ Tags: #Malware #Battlefield 6 #Bitdefender #Cybercrime #Fake Crack #Game Security #Infostealer #InsaneRamZes #malware #RUNE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:22:37 +0000
════════════════════════
⌗ Tags: #Malware #Battlefield 6 #Bitdefender #Cybercrime #Fake Crack #Game Security #Infostealer #InsaneRamZes #malware #RUNE
Daily CyberSecurity
Fragging Your Data: Fake ‘Battlefield 6’ Cracks & Trainers Spread Infostealers
The highly anticipated October release of EA’s Battlefield 6 has become a digital minefield for gamers. Bitdefender Labs has identified multiple active malware campaigns exploiting the shooter’s p…
⤷ Title: Hidden Danger in 3D: Malicious Blender Files Unleash StealC V2 Infostealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:19:01 +0000
════════════════════════
⌗ Tags: #Malware #3D Modeling #Blender #cybersecurity #Infostealer #malware #Morphisec #Python Scripts #StealC V2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:19:01 +0000
════════════════════════
⌗ Tags: #Malware #3D Modeling #Blender #cybersecurity #Infostealer #malware #Morphisec #Python Scripts #StealC V2
Daily CyberSecurity
Hidden Danger in 3D: Malicious Blender Files Unleash StealC V2 Infostealer
Alert: Malicious Blender files are delivering StealC V2 infostealer. 3D artists downloading from free sites are at risk. Disable auto-run scripts now.
⤷ Title: Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:14:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13315 #CVE_2025_13316 #IoT security #Media Server #Rapid7 #Twonky Server #Unpatched Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:14:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_13315 #CVE_2025_13316 #IoT security #Media Server #Rapid7 #Twonky Server #Unpatched Vulnerability #zero_day
Daily CyberSecurity
Zero-Day Warning: Unpatched Twonky Server Flaws Expose Media to Total Takeover
Critical alert: Twonky Server suffers unpatched flaws (CVE-2025-13315/16) allowing full takeover. Vendor has no fix; isolate your server immediately.
⤷ Title: UNMASKED: Massive Leak Exposes Iran’s ‘Department 40’ Cyber-Terror Unit
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #Abbas Rahrovi #APT35 #Assassination Plot #Charming Kitten #Cyber Terrorism #cybersecurity #Department 40 #Iran #IRGC #Nariman Gharib
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:10:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Data Leak #Abbas Rahrovi #APT35 #Assassination Plot #Charming Kitten #Cyber Terrorism #cybersecurity #Department 40 #Iran #IRGC #Nariman Gharib
Daily CyberSecurity
UNMASKED: Massive Leak Exposes Iran's 'Department 40' Cyber-Terror Unit
A massive leak exposes Iran's Department 40 (APT35). Discover how IRGC hackers build target packages for assassination squads and drone strikes.
⤷ Title: Angular Alert: Protocol-Relative URLs Leak XSRF Tokens (CVE-2025-66035)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:05:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CSRF #CVE_2025_66035 #Front_end Security #HTTP Client #javascript #Web Security #XSRF
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:05:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Angular #CSRF #CVE_2025_66035 #Front_end Security #HTTP Client #javascript #Web Security #XSRF
Daily CyberSecurity
Angular Alert: Protocol-Relative URLs Leak XSRF Tokens (CVE-2025-66035)
CVE-2025-66035: Angular protocol-relative URLs leak XSRF tokens, bypassing CSRF protection. Update to v19.2.16, v20.3.14, or v21.0.1 now.
⤷ Title: JWT Privilege Escalation to Container RCE via Jinja2 SSTI “ Intigriti challenge”
════════════════════════
𐀪 Author: Adham Heinrich
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:05:18 GMT
════════════════════════
⌗ Tags: #ctf_writeup #bugbounty_writeup #bug_bounty_tips #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Adham Heinrich
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:05:18 GMT
════════════════════════
⌗ Tags: #ctf_writeup #bugbounty_writeup #bug_bounty_tips #bug_bounty #cybersecurity
Medium
JWT Privilege Escalation to Container RCE via Jinja2 SSTI “ Intigriti challenge”
The application is a Flask-based e-commerce platform running inside a Docker container. The attack chain combines a JWT role forgery…
⤷ Title: Kali Linux: First Steps and Must-Have Tweaks
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:24:49 GMT
════════════════════════
⌗ Tags: #beginners_guide #penetration_testing #kali_linux #hacking #cybersecurity
════════════════════════
𐀪 Author: Aj
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:24:49 GMT
════════════════════════
⌗ Tags: #beginners_guide #penetration_testing #kali_linux #hacking #cybersecurity
Medium
Kali Linux: First Steps and Must-Have Tweaks
Your first stop in ethical hacking.
⤷ Title: How I Used Ligolo-ng to Pivot into Internal Networks During OSCP Labs
════════════════════════
𐀪 Author: Got Root?
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:24:37 GMT
════════════════════════
⌗ Tags: #linux #cybersecurity #technology #hacking #information_security
════════════════════════
𐀪 Author: Got Root?
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:24:37 GMT
════════════════════════
⌗ Tags: #linux #cybersecurity #technology #hacking #information_security
Medium
How I Used Ligolo-ng to Pivot into Internal Networks During OSCP Labs
During my OSCP labs and internal network simulations, I struggled with traditional pivoting tools like SSH tunneling and Chisel — either…
⤷ Title: HackTheBox DCSync: When Your User Account Thinks It’s a Domain Controller
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:32:11 GMT
════════════════════════
⌗ Tags: #information_security #hackthebox #hacking #women_in_tech #cybersecurity
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:32:11 GMT
════════════════════════
⌗ Tags: #information_security #hackthebox #hacking #women_in_tech #cybersecurity
Medium
HackTheBox DCSync: When Your User Account Thinks It’s a Domain Controller
DCSync is one of those attacks that sounds more complicated than it actually is. Here’s the concept: if an attacker has an account with the…
⤷ Title: Cybersecurity Homelab Setup (Using a Single Desktop)
════════════════════════
𐀪 Author: Johnny Meintel
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:44:24 GMT
════════════════════════
⌗ Tags: #infosec #homelab #cybersecurity
════════════════════════
𐀪 Author: Johnny Meintel
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:44:24 GMT
════════════════════════
⌗ Tags: #infosec #homelab #cybersecurity
Medium
Cybersecurity Homelab Setup (Using a Single Desktop)
You don’t need equipment to setup a homelab. I’ve got a desktop with 32GB of memory and 1TB of storage (it’s a OptiPlex 5070 + 2 monitors)…
⤷ Title: Fortinet FortiWeb Zero-Day (CVE-2025–64446): Risk Assessment and Defense Strategies
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:18:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #fortiweb #fortinet #zero_day #cve_2025_64446
════════════════════════
𐀪 Author: Criminal IP
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:18:53 GMT
════════════════════════
⌗ Tags: #cybersecurity #fortiweb #fortinet #zero_day #cve_2025_64446
Medium
Fortinet FortiWeb Zero-Day (CVE-2025–64446): Risk Assessment and Defense Strategies
A newly identified path traversal vulnerability in Fortinet FortiWeb allows attackers to bypass authentication and ultimately gain…
⤷ Title: My favorite Linux Command #4 — curl
════════════════════════
𐀪 Author: Balazs Kocsis
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:18:32 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #rest_api #linux_commands #linux
════════════════════════
𐀪 Author: Balazs Kocsis
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:18:32 GMT
════════════════════════
⌗ Tags: #technology #cybersecurity #rest_api #linux_commands #linux
Medium
My favorite Linux Command #4 — curl
The Swiss Army Knife of Every Developer
⤷ Title: Hunting Through the Gaps: Multi-Source Correlation — Part 2B
════════════════════════
𐀪 Author: Raynard Waits
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:02:09 GMT
════════════════════════
⌗ Tags: #blue_team #cybersecurity #soc_analyst #homelab #soc_analyst_training
════════════════════════
𐀪 Author: Raynard Waits
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:02:09 GMT
════════════════════════
⌗ Tags: #blue_team #cybersecurity #soc_analyst #homelab #soc_analyst_training
Medium
Hunting Through the Gaps: Multi-Source Correlation — Part 2B
In Part 2A, I discovered that only 33% of reconnaissance commands triggered SIEM alerts. Here’s how I found that gap: by using correlation…
⤷ Title: GraphicalProton.exe A Stealthy Stager Malware
════════════════════════
𐀪 Author: MalwareDoctor
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:44:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #cybercrime #malware_analysis
════════════════════════
𐀪 Author: MalwareDoctor
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:44:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #malware #cybercrime #malware_analysis
Medium
GraphicalProton.exe A Stealthy Stager Malware
An advanced reconnaissance tool designed to silently prepare infected hosts for long-term compromise.
⤷ Title: Between the Wires: A Practical Breakdown of Modern MITM (Man in the Middle) Attacks
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:26:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitm_attacks #mitmproxy #cybercrime #mitm
════════════════════════
𐀪 Author: Travis Ray Caverhill
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 00:26:59 GMT
════════════════════════
⌗ Tags: #cybersecurity #mitm_attacks #mitmproxy #cybercrime #mitm
Medium
Between the Wires: A Practical Breakdown of Modern MITM (Man in the Middle) Attacks
By: Travis Ray Caverhill aka Saltine Hacker
⤷ Title: FastAPI in Prod: Auth, Limits, Zero-Downtime
════════════════════════
𐀪 Author: Modexa
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:32:26 GMT
════════════════════════
⌗ Tags: #api_security #devops #scalability #fastapi #python
════════════════════════
𐀪 Author: Modexa
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:32:26 GMT
════════════════════════
⌗ Tags: #api_security #devops #scalability #fastapi #python
Medium
FastAPI in Prod: Auth, Limits, Zero-Downtime
A practical playbook to ship FastAPI services that stay secure, polite to your neighbors, and deploy without waking the on-call.
⤷ Title: Unlock X Benefits & Rewards — November 2025
════════════════════════
𐀪 Author: Theodore
Stewart
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:45:30 GMT
════════════════════════
⌗ Tags: #crypto #rewards #blockchain #bonus #xs
════════════════════════
𐀪 Author: Theodore
Stewart
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:45:30 GMT
════════════════════════
⌗ Tags: #crypto #rewards #blockchain #bonus #xs
Medium
X Airdrop Guide — Claim Tokens Now! 🚀 [November 2025]
Discover how to access and benefit from the latest X reward program.
⤷ Title: Wrapped SOL Rewards Eligibility & Claim Guide — November 2025
════════════════════════
𐀪 Author: Justin
Martin
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:18:22 GMT
════════════════════════
⌗ Tags: #rewards #xs #blockchain #eligibility #crypto
════════════════════════
𐀪 Author: Justin
Martin
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 01:18:22 GMT
════════════════════════
⌗ Tags: #rewards #xs #blockchain #eligibility #crypto
Medium
Claim $X » Wrapped SOL Airdrop — Eligibility & Claim Info — [November 2025]
Everything you need to know to understand and access Wrapped SOL rewards.
⤷ Title: Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 03:22:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache SkyWalking #APM Security #Cloud Native Security #CVE_2025_54057 #Stored XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 03:22:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache SkyWalking #APM Security #Cloud Native Security #CVE_2025_54057 #Stored XSS
Daily CyberSecurity
Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057)
Apache SkyWalking patches a Stored XSS flaw (CVE-2025-54057) affecting versions 10.2.0 and older. Upgrade to v10.3.0 to secure your APM dashboards.
⤷ Title: Hidden Theft: ‘Crypto Copilot’ Chrome Extension Drains Solana Wallets on X
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 02:13:43 +0000
════════════════════════
⌗ Tags: #Malware #Chrome extension #Crypto Copilot #Cryptocurrency Scam #Infostealer #malware #Socket #Solana #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 27 Nov 2025 02:13:43 +0000
════════════════════════
⌗ Tags: #Malware #Chrome extension #Crypto Copilot #Cryptocurrency Scam #Infostealer #malware #Socket #Solana #Web3 security
Daily CyberSecurity
Hidden Theft: 'Crypto Copilot' Chrome Extension Drains Solana Wallets on X
The malicious 'Crypto Copilot' Chrome extension drains Solana funds from traders on X by injecting hidden transfers. Remove this malware immediately.