⤷ Title: High-Severity Jenkins Flaws Risk Unauthenticated DoS via HTTP CLI and XSS Via Coverage Reports
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:38:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Build Token #CI/CD #Coverage Plugin #CVE_2025_67635 #dos #HTTP CLI #Jenkins #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:38:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Build Token #CI/CD #Coverage Plugin #CVE_2025_67635 #dos #HTTP CLI #Jenkins #XSS
Daily CyberSecurity
High-Severity Jenkins Flaws Risk Unauthenticated DoS via HTTP CLI and XSS Via Coverage Reports
Jenkins patched nine flaws: a High-severity unauthenticated DoS (CVE-2025-67635) via HTTP CLI and XSS via Coverage Plugin. Build tokens are now encrypted. Update to v2.541 immediately.
⤷ Title: Gogs Zero-Day (CVE-2025-8110) Risks RCE for 700+ Servers via Symlink Path Traversal Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:16:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_8110 #Git Service #Gogs #Path Traversal #rce #SUPERSHELL #Symlink #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 02:16:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_8110 #Git Service #Gogs #Path Traversal #rce #SUPERSHELL #Symlink #zero_day
Daily CyberSecurity
Gogs Zero-Day (CVE-2025-8110) Risks RCE for 700+ Servers via Symlink Path Traversal Bypass
A Gogs zero-day (CVE-2025-8110) bypasses a previous patch, enabling RCE via symlink path traversal. Over 50% of exposed instances are compromised, deploying the Supershell C2. Disable open registration immediately.
⤷ Title: High-Severity GitLab XSS Flaw (CVE-2025-12716) Risks Session Hijack via Malicious Wiki Pages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 01:46:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_12716 #gitlab #HTML Injection #Information Disclosure #Session Hijack #Wiki #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 01:46:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_12716 #gitlab #HTML Injection #Information Disclosure #Session Hijack #Wiki #XSS
Daily CyberSecurity
High-Severity GitLab XSS Flaw (CVE-2025-12716) Risks Session Hijack via Malicious Wiki Pages
A High-severity XSS (CVSS 8.7) flaw in GitLab Wiki allows session hijack via malicious pages, enabling unauthorized actions. Other HTML Injection flaws patched. Self-managed admins must update to v18.6.2.
⤷ Title: Facebook Gets New Look, But Instagram Secretly Uses AI for SEO Bait
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:44:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #404 Media #AI #AI Ethics #App Update #Content Farm #facebook #Instagram #Meta #Redesign #SEO #Social Media
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:44:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #404 Media #AI #AI Ethics #App Update #Content Farm #facebook #Instagram #Meta #Redesign #SEO #Social Media
Daily CyberSecurity
Facebook Gets New Look, But Instagram Secretly Uses AI for SEO Bait
Meta rolls out a transparent Facebook redesign for better navigation. Meanwhile, Instagram is secretly using AI to generate "content-farm" titles in code to boost Google SEO.
⤷ Title: SpaceX IPO: Targeting a $1.5 Trillion Valuation to Fund Space Data Centers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:40:25 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Elon Musk #IPO #Record Breaking #Saudi Aramco #Space Data Centers #SpaceX #Starlink #Starship #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:40:25 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Elon Musk #IPO #Record Breaking #Saudi Aramco #Space Data Centers #SpaceX #Starlink #Starship #valuation
Daily CyberSecurity
SpaceX IPO: Targeting a $1.5 Trillion Valuation to Fund Space Data Centers
SpaceX is planning a record-shattering IPO in 2026/2027 to raise over $30B, targeting a $1.5T valuation. Proceeds will fund Mars ambitions and orbital AI data centers.
⤷ Title: China’s WARP PANDA APT Deploys BRICKSTORM Backdoor to Hijack VMware vCenter/ESXi and Azure Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:36:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BRICKSTORM #China APT #Cloud Espionage #DoH #ESXi #Microsoft Azure #vCenter #vmware #WARP PANDA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:36:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #BRICKSTORM #China APT #Cloud Espionage #DoH #ESXi #Microsoft Azure #vCenter #vmware #WARP PANDA
Daily CyberSecurity
China's WARP PANDA APT Deploys BRICKSTORM Backdoor to Hijack VMware vCenter/ESXi and Azure Cloud
China-nexus WARP PANDA APT targets VMware/Azure with BRICKSTORM, a Golang backdoor using DoH for stealth. The group creates "ghost VMs" and conducts session replay attacks for long-term espionage.
⤷ Title: Unpatched TOTOLINK AX1800 Router Flaw Allows Unauthenticated Telnet & Root RCE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:31:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13184 #rce #root access #Router Flaw #Telnet #TOTOLINK
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:31:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13184 #rce #root access #Router Flaw #Telnet #TOTOLINK
Daily CyberSecurity
Unpatched TOTOLINK AX1800 Router Flaw Allows Unauthenticated Telnet & Root RCE
A critical unpatched flaw in the TOTOLINK AX1800 router allows unauthenticated HTTP requests to enable Telnet for root RCE. Admins must block WAN access immediately as there is no official fix.
⤷ Title: FBI/CISA Warn: Pro-Russia Hacktivists Target Critical Infrastructure Via Unsecured VNC HMIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:27:44 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA #Critical Infrastructure #Cyber Army of Russia Reborn #fbi #Hacktivism #HMI #OT Security #vnc
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:27:44 +0000
════════════════════════
⌗ Tags: #Cyber Security #CISA #Critical Infrastructure #Cyber Army of Russia Reborn #fbi #Hacktivism #HMI #OT Security #vnc
Daily CyberSecurity
FBI/CISA Warn: Pro-Russia Hacktivists Target Critical Infrastructure Via Unsecured VNC HMIs
FBI/CISA warn pro-Russia hacktivists (CARR, NoName057) are targeting critical infrastructure with unsophisticated attacks. They exploit unsecured VNC connections to manipulate HMIs and cause physical damage.
⤷ Title: Critical CCTV Flaw (CVE-2025-13607) Risks Video Feed Hijack & Credential Theft via Missing Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:22:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CCTV #Credential Theft #Critical Vulnerability #CVE_2025_13607 #D_Link #Missing Authentication #Video Surveillance
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:22:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CCTV #Credential Theft #Critical Vulnerability #CVE_2025_13607 #D_Link #Missing Authentication #Video Surveillance
Daily CyberSecurity
Critical CCTV Flaw (CVE-2025-13607) Risks Video Feed Hijack & Credential Theft via Missing Authentication
CISA warned of a Critical (CVSS 9.4) flaw in D-Link DCS-F5614-L1 cameras. Missing Authentication allows attackers to bypass login, steal admin credentials, and hijack video feeds. Patch immediately.
⤷ Title: “React2Shell” Crisis: Critical Vulnerability Triggers Global Cyberattacks by State-Sponsored Groups
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_55182 #Deserialization #Next.js #rce #React Server Components #React2Shell #state_sponsored
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:19:19 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_55182 #Deserialization #Next.js #rce #React Server Components #React2Shell #state_sponsored
Daily CyberSecurity
"React2Shell" Crisis: Critical Vulnerability Triggers Global Cyberattacks by State-Sponsored Groups
A Critical RCE (CVSS 10.0) flaw, React2Shell, in React/Next.js's Flight protocol allows unauthenticated system takeover. North Korean and Chinese state actors are actively exploiting the deserialization bug.
⤷ Title: Makop Ransomware Evolves: GuLoader and BYOVD EDR Killers Used to Attack RDP-Exposed Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:14:06 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Cybercrime #EDR Killer #GuLoader #India #Makop ransomware #Phobos #RDP Brute Force
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:14:06 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #Cybercrime #EDR Killer #GuLoader #India #Makop ransomware #Phobos #RDP Brute Force
Daily CyberSecurity
Makop Ransomware Evolves: GuLoader and BYOVD EDR Killers Used to Attack RDP-Exposed Networks
Makop ransomware operators now use GuLoader and BYOVD (ThrottleStop.sys) to bypass EDR and security. The "low-effort" campaign targets RDP-exposed networks, with 55% of attacks aimed at India.
⤷ Title: DeadLock Ransomware Deploys BYOVD EDR Killer by Exploiting Baidu Driver for Kernel-Level Defense Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:06:01 +0000
════════════════════════
⌗ Tags: #Malware #AnyDesk #Baidu Driver #BYOVD #Custom Cipher #CVE_2024_51324 #DeadLock Ransomware #EDR Killer #Kernel Privilege
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 00:06:01 +0000
════════════════════════
⌗ Tags: #Malware #AnyDesk #Baidu Driver #BYOVD #Custom Cipher #CVE_2024_51324 #DeadLock Ransomware #EDR Killer #Kernel Privilege
Daily CyberSecurity
DeadLock Ransomware Deploys BYOVD EDR Killer by Exploiting Baidu Driver for Kernel-Level Defense Bypass
DeadLock Ransomware uses BYOVD (Baidu driver exploit) and the EDRGay.exe loader to kill EDR/AV at the kernel level. It uses a custom stream cipher and deletes shadow copies to prevent recovery.
⤷ Title: Google XSS Game Solution
════════════════════════
𐀪 Author: Blueorionn
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:42:15 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #penetration_testing #coding #cybersecurity
════════════════════════
𐀪 Author: Blueorionn
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:42:15 GMT
════════════════════════
⌗ Tags: #ctf #bug_bounty #penetration_testing #coding #cybersecurity
Medium
Google XSS Game Solution
This article is a walkthrough guide to solving the challenges in the Google XSS Game on Appspot.
⤷ Title: Password Security Best Practices: Beyond ‘123456’
════════════════════════
𐀪 Author: Haxman
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:29:24 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #strong_password_security
════════════════════════
𐀪 Author: Haxman
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:29:24 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #strong_password_security
Medium
Password Security Best Practices: Beyond ‘123456’
Despite years of warnings, “123456” and “password” remain among the most common passwords. In an age of billion-record data breaches, weak…
⤷ Title: AI in Cybersecurity: The Double-Edged Sword of 2025
════════════════════════
𐀪 Author: Haxman
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:27:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty #free_tools
════════════════════════
𐀪 Author: Haxman
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:27:49 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_tips #bug_bounty #free_tools
Medium
AI in Cybersecurity: The Double-Edged Sword of 2025
Artificial Intelligence (AI) has revolutionized every industry, and cybersecurity is no exception. In 2025, we are witnessing a digital…
⤷ Title: Bug Bounty Journey: From Discovery to $800 Reward
════════════════════════
𐀪 Author: Milan Gautam
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:13:45 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #cybersecurity #vulnerability #open_redirect
════════════════════════
𐀪 Author: Milan Gautam
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 05:13:45 GMT
════════════════════════
⌗ Tags: #web_security #bug_bounty #cybersecurity #vulnerability #open_redirect
Medium
Bug Bounty Journey: From Discovery to $800 Reward
The $800 Parameter: How One Unsanitized Input Revealed a Global Security Gap
⤷ Title: PayPal’s SDK URLs Leak Merchant Emails and Client IDs – A PII Goldmine Dismissed as "Informative"…
════════════════════════
𐀪 Author: ElonMuskTheAntichrist
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:16:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #infosec_write_ups #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: ElonMuskTheAntichrist
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:16:16 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #infosec_write_ups #bug_bounty #bug_bounty_writeup
Medium
PayPal’s SDK URLs Leak Merchant Emails and Client IDs – A PII Goldmine Dismissed as "Informative"…
CRITICAL FINDING! Massive leaked merchant emails along with client IDs in public PayPal SDK URL. A major PII data leak.
⤷ Title: Tải Bus Simulator Vietnam Apk (MOD Bản Full ) v9.3.8
════════════════════════
𐀪 Author: genzvnmod
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:26:56 GMT
════════════════════════
⌗ Tags: #games #genzvnmod #hacking
════════════════════════
𐀪 Author: genzvnmod
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:26:56 GMT
════════════════════════
⌗ Tags: #games #genzvnmod #hacking
Medium
Tải Bus Simulator Vietnam Apk (MOD Bản Full ) v9.3.8
Bus Simulator Vietnam là một tựa game mô phỏng lái xe buýt tại Việt Nam, mang đến trải nghiệm chân thực trên các tuyến đường và địa danh…
⤷ Title: You Can Get Hacked Without Clicking Anything. AI Just Made It Easier.
════════════════════════
𐀪 Author: Pasan Madhuranga
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:07:16 GMT
════════════════════════
⌗ Tags: #data_privacy #artificial_intelligence #hacking #cybersecurity #technology
════════════════════════
𐀪 Author: Pasan Madhuranga
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:07:16 GMT
════════════════════════
⌗ Tags: #data_privacy #artificial_intelligence #hacking #cybersecurity #technology
Medium
Zero-Click Attacks & AI Agents: The Silent Threat You Never Saw Coming
Imagine waking up, grabbing your phone, and discovering someone has already rummaged through your camera, microphone, emails, messages —…
⤷ Title: Tải Hack Car Parking Multiplayer (Mod Full Tiền) V4.9.5.2 Trên Android
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:04:34 GMT
════════════════════════
⌗ Tags: #hacking #apkpure #games
════════════════════════
𐀪 Author: Apkpuredev
════════════════════════
ⴵ Time: Thu, 11 Dec 2025 04:04:34 GMT
════════════════════════
⌗ Tags: #hacking #apkpure #games
Medium
Tải Hack Car Parking Multiplayer (Mod Full Tiền) V4.9.5.2 Trên Android
Car Parking Multiplayer là một tựa game mô phỏng lái xe và đậu xe theo phong cách thế giới mở, nơi người chơi có thể điều khiển nhiều loại…