⤷ Title: Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache HTTP Server #CVE_2025_59775 #NTLM Leak #ssrf #suexec Bypass #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:06:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache HTTP Server #CVE_2025_59775 #NTLM Leak #ssrf #suexec Bypass #Windows Security
Daily CyberSecurity
Apache HTTP Server 2.4.66 Fixes SSRF Flaw (CVE-2025-59775) Exposing NTLM Hashes on Windows and suexec Bypass
Apache HTTP Server 2.4.66 patched five flaws. Key fixes include a moderate SSRF flaw (CVE-2025-59775) that risks NTLM hash leakage on Windows, and a mod_userdir/suexec bypass. Update immediately.
⤷ Title: Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy “Smart Mining” Evasion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:39:33 +0000
════════════════════════
⌗ Tags: #Malware #ASEC #CoinMiner #cryptomining #DLL side_loading #PrintMiner #Smart Mining #USB malware #XMRig
Daily CyberSecurity
Stealth Cryptominer Uses USB LNK and DLL Side-Loading to Deploy "Smart Mining" Evasion
ASEC exposed PrintMiner, a Monero cryptominer spreading via USB LNK files. It uses DLL Side-Loading (printui.exe) and "Smart Mining" to suspend activity when games or Task Manager are opened.
⤷ Title: The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:21:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:21:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
Daily CyberSecurity
The PDF Trap: Critical Vulnerability (CVE-2025-66516, CVSS 10.0) Hits Apache Tika Core
Apache patched a Catastrophic XXE flaw (CVE-2025-66516, CVSS 10.0) in Tika Core. The bug is exploitable via malicious XFA data inside a PDF, risking server-side data disclosure and RCE. Update immediately.
⤷ Title: “React2Shell” Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #rce #React Server Components #React2Shell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 02:09:05 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #APT #CVE_2025_55182 #Earth Lamia #Jackpot Panda #rce #React Server Components #React2Shell #zero_day
Daily CyberSecurity
"React2Shell" Storm: China-Nexus Groups Weaponize Critical React Flaw Hours After Disclosure
Amazon exposed Chinese APTs exploiting the React2Shell zero-day (CVE-2025-55182, CVSS 10.0) hours after disclosure. Earth Lamia and Jackpot Panda are actively targeting unpatched Next.js servers for reconnaissance.
⤷ Title: Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Malware #Adaptix C2 #DUPERUNNER #HR Targets #LNK Exploit #Process injection #russia #spear_phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:35:53 +0000
════════════════════════
⌗ Tags: #Malware #Adaptix C2 #DUPERUNNER #HR Targets #LNK Exploit #Process injection #russia #spear_phishing
Daily CyberSecurity
Operation DUPEHIKE Hits Russian HR: Bonus Lure Delivers DUPERUNNER and Adaptix C2 via Process Injection
SEQRITE exposed Operation DUPEHIKE targeting Russian HR with a malicious LNK bonus lure. The DUPERUNNER implant uses PowerShell and process injection into explorer.exe to deploy the Adaptix C2 Beacon.
⤷ Title: High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:30:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_20386 #Incorrect Permissions #privilege escalation #Splunk #Universal Forwarder #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:30:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_20386 #Incorrect Permissions #privilege escalation #Splunk #Universal Forwarder #Windows Security
Daily CyberSecurity
High-Severity Splunk Flaw Allows Local Privilege Escalation via Incorrect File Permissions on Windows
A High-severity flaw (CVSS 8.0) in Splunk Enterprise/Universal Forwarder for Windows allows low-privileged users to access/tamper with sensitive installation directories due to incorrect permissions. Update to v10.0.2+.
⤷ Title: High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:22:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cacti #Command Injection #CVE_2025_66399 #network monitoring #rce #security patch #SNMP Community String
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:22:39 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cacti #Command Injection #CVE_2025_66399 #network monitoring #rce #security patch #SNMP Community String
Daily CyberSecurity
High-Severity Cacti Flaw (CVE-2025-66399) Risks Remote Code Execution via SNMP Community String Injection
A High-severity RCE flaw (CVE-2025-66399) in Cacti allows authenticated attackers to execute commands by injecting newline characters into the SNMP Community String. Update to v1.2.29 immediately.
⤷ Title: Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and “Missing File” Lure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:19:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #AitM Phishing #Calisto #COLDRIVER #Espionage #Reporters Without Borders #RSF #Russian APT #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:19:51 +0000
════════════════════════
⌗ Tags: #Cyber Security #AitM Phishing #Calisto #COLDRIVER #Espionage #Reporters Without Borders #RSF #Russian APT #social engineering
Daily CyberSecurity
Russian Calisto APT Targets Reporters Without Borders with Custom AiTM Phishing and "Missing File" Lure
Sekoia exposed Russian Calisto APT (FSB-linked) targeting RSF and NGOs with spear-phishing. The attack uses a custom AiTM kit and a "missing file" lure to steal credentials and 2FA codes.
⤷ Title: NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:11:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2025_33211 #Denial of Service #dos #Inference Server #MLOps #NVIDIA Triton
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:11:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2025_33211 #Denial of Service #dos #Inference Server #MLOps #NVIDIA Triton
Daily CyberSecurity
NVIDIA Triton Server Patches Two High-Severity DoS Flaws, Risking Critical AI Inference Disruption
NVIDIA patched two high-severity DoS flaws in Triton Inference Server (CVE-2025-33211, CVE-2025-33201). Attackers can crash the server by sending malformed or excessively large payloads. Update to r25.10 immediately.
⤷ Title: Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #File Transfer #LNK File #Patchwork #persistence #StreamSpy #WebSocket C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:06:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #File Transfer #LNK File #Patchwork #persistence #StreamSpy #WebSocket C2
Daily CyberSecurity
Patchwork APT Deploys StreamSpy Trojan, Hiding C2 Commands in WebSocket Traffic for Stealth Espionage
Patchwork APT deployed StreamSpy, a new trojan that uses WebSocket for covert C2 and HTTP for file transfer, blending malicious activity with web traffic to evade detection during espionage operations.
⤷ Title: AI Demand Struggles: Microsoft Slashes Enterprise AI Sales Quotas by Up to 50%
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:03:14 +0000
════════════════════════
⌗ Tags: #Technology #AI Sales #Azure #enterprise AI #Microsoft #Microsoft Foundry #Sales Quota #Stock Price #The Information
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 00:03:14 +0000
════════════════════════
⌗ Tags: #Technology #AI Sales #Azure #enterprise AI #Microsoft #Microsoft Foundry #Sales Quota #Stock Price #The Information
Daily CyberSecurity
AI Demand Struggles: Microsoft Slashes Enterprise AI Sales Quotas by Up to 50%
Microsoft reportedly slashed enterprise AI sales quotas by up to 50% after teams struggled to meet targets for platforms like Azure and Microsoft Foundry.
⤷ Title: ️ How I Walked Into LaunchDarkly’s Internal Jira Portal Through a Public Signup Bug
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:25:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #security_misconfiguration #hackerone #hacking
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:25:28 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #security_misconfiguration #hackerone #hacking
Medium
🗂️ How I Walked Into LaunchDarkly’s Internal Jira Portal Through a Public Signup Bug
Bug bounty hunting is wild sometimes. One minute you’re casually poking around, and the next you’ve slipped straight into a company’s…
⤷ Title: ️♂️ How I Stumbled Into My First Uber Bug: The Unexpected Win That Earned Me $780
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:20:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #cybersecurity #storytelling #hackerone
════════════════════════
𐀪 Author: Anshubind
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:20:43 GMT
════════════════════════
⌗ Tags: #bug_bounty #ethical_hacking #cybersecurity #storytelling #hackerone
Medium
🕵️♂️ How I Stumbled Into My First Uber Bug: The Unexpected Win That Earned Me $780
You know that moment in bug bounty hunting when you’re not even expecting anything big… and then suddenly you’re staring at an admin panel…
⤷ Title: Breaking the Web (Part 6): Insecure Direct Object References (IDOR) — When Access Control Fails
════════════════════════
𐀪 Author: Mohammed Fahad
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:17:34 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #cybersecurity #web_application_security #cyber_security_awareness
════════════════════════
𐀪 Author: Mohammed Fahad
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:17:34 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #cybersecurity #web_application_security #cyber_security_awareness
Medium
Breaking the Web (Part 6): Insecure Direct Object References (IDOR) — When Access Control Fails
Some vulnerabilities exist not because of complex bugs… …but because developers trust the user far more than they should.
⤷ Title: Bug Bounty Hunting — Complete Guide (Part-155)
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:40:33 GMT
════════════════════════
⌗ Tags: #hacking #ethical_hacking #bug_bounty_tips #bug_bounty #cybersecurity
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:40:33 GMT
════════════════════════
⌗ Tags: #hacking #ethical_hacking #bug_bounty_tips #bug_bounty #cybersecurity
Medium
Bug Bounty Hunting — Complete Guide (Part-155)
📥 HTTP Response Headers: A Detailed Look
⤷ Title: Bug Bounty Hunting — Complete Guide (Part-154)
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:38:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty #ethical_hacking #hacking
════════════════════════
𐀪 Author: Mehedi Hasan Rafid
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:38:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty #ethical_hacking #hacking
Medium
Bug Bounty Hunting — Complete Guide (Part-154)
The provided text is an introduction to the Resource Timing API, a JavaScript feature used for diagnosing web page performance.
⤷ Title: How Misconfigured Authentication Broke One App - And How We Fixed It (Sanitized Walkthrough)
════════════════════════
𐀪 Author: Krutik Thakar — Secure Developer | VAPT Associate
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:37:22 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #vapt #secure_development #authentication
════════════════════════
𐀪 Author: Krutik Thakar — Secure Developer | VAPT Associate
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:37:22 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #vapt #secure_development #authentication
Medium
How Misconfigured Authentication Broke One App - And How We Fixed It (Sanitized Walkthrough)
A safe VAPT case study showing how authentication misconfigurations are discovered, abused conceptually, and fixed with secure patterns.
⤷ Title: Path Traversal: Because Hackers Also Love Taking Shortcuts
════════════════════════
𐀪 Author: TheCyberAryan
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:49:32 GMT
════════════════════════
⌗ Tags: #vulnerability #path_traversal #hacking #web_development #cybersecurity
════════════════════════
𐀪 Author: TheCyberAryan
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:49:32 GMT
════════════════════════
⌗ Tags: #vulnerability #path_traversal #hacking #web_development #cybersecurity
Medium
Path Traversal: Because Hackers Also Love Taking Shortcuts
If you’ve ever watched a hacker poke a website, you’ll notice something magical: they almost always try to open files they were never…
⤷ Title: IOT Connect Writeup — MobileHackingLab
════════════════════════
𐀪 Author: محمد بن إبراهيم
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:26:28 GMT
════════════════════════
⌗ Tags: #hacking #android #mobile #ctf #penetration_testing
════════════════════════
𐀪 Author: محمد بن إبراهيم
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 04:26:28 GMT
════════════════════════
⌗ Tags: #hacking #android #mobile #ctf #penetration_testing
Medium
IOT Connect Writeup — MobileHackingLab
بسم الله الرحمن الرحيم
⤷ Title: React2Shell (CVE-2025–55182): What Developers Need to Know
════════════════════════
𐀪 Author: HectoGen
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:57:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #nextjs #hacking #react
════════════════════════
𐀪 Author: HectoGen
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:57:10 GMT
════════════════════════
⌗ Tags: #cybersecurity #nextjs #hacking #react
Medium
React2Shell (CVE-2025–55182): What Developers Need to Know
A critical vulnerability in React has recently sent shockwaves through the web development community. Known as React2Shell…
⤷ Title: SQL Injection Explained: From Basic to Advanced Exploitation (Complete Technical Guide)
════════════════════════
𐀪 Author: Handev Code
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:53:17 GMT
════════════════════════
⌗ Tags: #information_security #web_security #hacking #cybersecurity #backend_development
════════════════════════
𐀪 Author: Handev Code
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 05:53:17 GMT
════════════════════════
⌗ Tags: #information_security #web_security #hacking #cybersecurity #backend_development
Medium
SQL Injection Explained: From Basic to Advanced Exploitation (Complete Technical Guide)
SQL Injection (SQLi) adalah salah satu kerentanan paling kritis dalam keamanan aplikasi modern. Artikel ini memberikan penjelasan teknis…