⤷ Title: Directory Transversal lead to RCE | Manual hacking.
════════════════════════
𐀪 Author: Alejandro Estupiñán
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 21:22:00 GMT
════════════════════════
⌗ Tags: #application_security #web_development #offensive_security #owasp #hacking
════════════════════════
𐀪 Author: Alejandro Estupiñán
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 21:22:00 GMT
════════════════════════
⌗ Tags: #application_security #web_development #offensive_security #owasp #hacking
Medium
Directory Transversal lead to RCE | Manual hacking.
High (8.6)
⤷ Title: The Salt of the Earth
════════════════════════
𐀪 Author: Amy Potter
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 21:39:43 GMT
════════════════════════
⌗ Tags: #short_fiction #short_story #crime #thriller #hacking
════════════════════════
𐀪 Author: Amy Potter
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 21:39:43 GMT
════════════════════════
⌗ Tags: #short_fiction #short_story #crime #thriller #hacking
Medium
The Salt of the Earth
(A crime thriller about a powerful mobster whose clinical worldview is shattered when he hires a hacker with a devastatingly strategic…
⤷ Title: Try Hack Me- Brooklyn Nine Nine Walkthrough
════════════════════════
𐀪 Author: Herrfuhrer
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 20:34:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_walkthrough #tryhackme #tryhackme_writeup #penetration_testing
════════════════════════
𐀪 Author: Herrfuhrer
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 20:34:26 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_walkthrough #tryhackme #tryhackme_writeup #penetration_testing
Medium
Try Hack Me- Brooklyn Nine Nine Walkthrough
Let’s do it!!!
⤷ Title: TryHackMe: Advent of Cyber 2025 — Day 15 Walkthrough
════════════════════════
𐀪 Author: Inyanji Lynnette
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 21:26:16 GMT
════════════════════════
⌗ Tags: #web_attack_forensics #advent_of_cyber25_day15 #splunk #advent_of_cyber_2025 #tryhackme
════════════════════════
𐀪 Author: Inyanji Lynnette
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 21:26:16 GMT
════════════════════════
⌗ Tags: #web_attack_forensics #advent_of_cyber25_day15 #splunk #advent_of_cyber_2025 #tryhackme
Medium
TryHackMe: Advent of Cyber 2025 — Day 15 Walkthrough
Web Attack Forensics — Drone Alone
⤷ Title: Juicy-Details THMWalkthrough
════════════════════════
𐀪 Author: TalentedH@cker
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 19:56:54 GMT
════════════════════════
⌗ Tags: #juicy_details_tryhackme #cybersecurity #tryhackme
════════════════════════
𐀪 Author: TalentedH@cker
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 19:56:54 GMT
════════════════════════
⌗ Tags: #juicy_details_tryhackme #cybersecurity #tryhackme
Medium
Juicy-Details THMWalkthrough
Let us enter the room tentatively, let us enter the room…
⤷ Title: Why I Care About Cybersecurity, UX, and Anti-fragile Systems
════════════════════════
𐀪 Author: Casandra Cain
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 23:50:08 GMT
════════════════════════
⌗ Tags: #hacking #systems_thinking #cybersecurity #user_experience #antifragile
════════════════════════
𐀪 Author: Casandra Cain
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 23:50:08 GMT
════════════════════════
⌗ Tags: #hacking #systems_thinking #cybersecurity #user_experience #antifragile
Medium
Why I Care About Cybersecurity, UX, and Anti-fragile Systems
Designing Anti-fragile Systems for a Hostile World
⤷ Title: Advent of Cyber 2025 Day 15 | TryHackMe | Web Attack Forensics - Drone Alone | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 23:23:29 GMT
════════════════════════
⌗ Tags: #tryhackme #splunk #tryhackme_writeup #tryhackme_walkthrough #advent_of_cyber_2025
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 23:23:29 GMT
════════════════════════
⌗ Tags: #tryhackme #splunk #tryhackme_writeup #tryhackme_walkthrough #advent_of_cyber_2025
Medium
Advent of Cyber 2025 Day 15 | TryHackMe | Web Attack Forensics - Drone Alone | WriteUp
Explore web attack forensics using Splunk
⤷ Title: Redeemer (HTB)
════════════════════════
𐀪 Author: Ethan Walker
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 22:11:19 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #hackthebox #hackthebox_writeup #learning
════════════════════════
𐀪 Author: Ethan Walker
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 22:11:19 GMT
════════════════════════
⌗ Tags: #hackthebox_walkthrough #hackthebox #hackthebox_writeup #learning
Medium
Redeemer (HTB)
Hack The Box Starting-Point
⤷ Title: Critical FortiGate SSO Flaw Under Active Exploitation: Attackers Bypass Auth and Exfiltrate Configs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:58:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Authentication Bypass #CVE_2025_59718 #FortiCloud #FortiGate #Fortinet #SAML #SSO Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:58:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #Authentication Bypass #CVE_2025_59718 #FortiCloud #FortiGate #Fortinet #SAML #SSO Bypass
Daily CyberSecurity
Critical FortiGate SSO Flaw Under Active Exploitation: Attackers Bypass Auth and Exfiltrate Configs
A critical FortiGate SSO flaw (CVSS 9.1) is under active exploitation, letting unauthenticated attackers bypass login via crafted SAML. The flaw is armed by default registration, risking config exfiltration. Patch immediately.
⤷ Title: 5-Year Threat: Malicious NuGet Package Used Homoglyphs and Typosquatting to Steal Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:45:36 +0000
════════════════════════
⌗ Tags: #Malware #.NET #Crypto Stealer #Fody #Homoglyph #NuGet #Stratis #supply chain attack #Tracer.Fody.NLog #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:45:36 +0000
════════════════════════
⌗ Tags: #Malware #.NET #Crypto Stealer #Fody #Homoglyph #NuGet #Stratis #supply chain attack #Tracer.Fody.NLog #Typosquatting
Daily CyberSecurity
5-Year Threat: Malicious NuGet Package Used Homoglyphs and Typosquatting to Steal Crypto Wallets
A malicious NuGet package (Tracer.Fody.NLog) stole crypto wallet data for 5 years using homoglyphs and typosquatting to evade detection. The .NET supply chain attack linked to a Russian C2 server.
⤷ Title: macOS LPE Flaw Resurfaces: .localized Directory Exploited to Hijack Installers and Gain Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:40:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.localized #CVE_2025_24099 #Installer Hijack #Local Privilege Escalation #LPE #macOS #root access #Third_Party Software
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:40:04 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #.localized #CVE_2025_24099 #Installer Hijack #Local Privilege Escalation #LPE #macOS #root access #Third_Party Software
Daily CyberSecurity
macOS LPE Flaw Resurfaces: .localized Directory Exploited to Hijack Installers and Gain Root Access
A macOS LPE flaw resurfaces after 7 years, allowing unprivileged users to hijack third-party installers and gain root access. The exploit leverages the hidden .localized directory to confuse the installation path.
⤷ Title: Frogblight Android Banking Trojan Targets Turkey via Fake E-Gov Smishing and WebView
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:32:19 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #Coper #Frogblight #MaaS #smishing #spyware #Turkey #WebView
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:32:19 +0000
════════════════════════
⌗ Tags: #Malware #Android trojan #banking malware #Coper #Frogblight #MaaS #smishing #spyware #Turkey #WebView
Daily CyberSecurity
Frogblight Android Banking Trojan Targets Turkey via Fake E-Gov Smishing and WebView
Frogblight, a new Android banking Trojan, is targeting Turkey via smishing with fake e-government apps. It uses WebView to steal credentials and is linked to the Coper MaaS family. It is being actively developed.
⤷ Title: Phantom Stealer Targets Russian Finance with ISO Phishing, Deploying Keyloggers and Crypto-Wallet Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:27:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Financial Sector #information stealer #ISO File #Keylogger #Phantom Stealer #phishing #russia #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:27:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Crypto theft #Financial Sector #information stealer #ISO File #Keylogger #Phantom Stealer #phishing #russia #social engineering
Daily CyberSecurity
Phantom Stealer Targets Russian Finance with ISO Phishing, Deploying Keyloggers and Crypto-Wallet Theft
Operation MoneyMount-ISO targets Russian financial institutions with a Phantom Stealer info-stealer hidden in an ISO file. The malware steals crypto wallets, browser data, and uses a keylogger. It has a SelfDestruct function for evasion.
⤷ Title: PyStoreRAT Uncovered: Fileless RAT Hides in Fake GitHub Repos to Launch Invisible Attacks on Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:22:06 +0000
════════════════════════
⌗ Tags: #Malware #CrowdStrike Evasion #fileless #github #HTA #PyStoreRAT #rat #Remote Access Trojan #Rhadamanthys #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:22:06 +0000
════════════════════════
⌗ Tags: #Malware #CrowdStrike Evasion #fileless #github #HTA #PyStoreRAT #rat #Remote Access Trojan #Rhadamanthys #Supply Chain
Daily CyberSecurity
PyStoreRAT Uncovered: Fileless RAT Hides in Fake GitHub Repos to Launch Invisible Attacks on Developers
PyStoreRAT, a new fileless RAT, is spreading via fake GitHub repositories targeting developers. It executes as a JS implant via mshta.exe and includes explicit evasion logic against CrowdStrike.
⤷ Title: BlackForce PhaaS Weaponizes React and Stateful Sessions to Bypass MFA & Steal Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackForce #Credential Theft #Man_in_the_Browser #MFA Bypass #PhaaS #Phishing_as_a_Service #React #SessionStorage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackForce #Credential Theft #Man_in_the_Browser #MFA Bypass #PhaaS #Phishing_as_a_Service #React #SessionStorage
Daily CyberSecurity
BlackForce PhaaS Weaponizes React and Stateful Sessions to Bypass MFA & Steal Credentials
BlackForce, a new PhaaS kit, is being sold for €300, using React/React Router to disguise its code. It utilizes stateful sessions and MitB to bypass MFA in real time. Update to V5 shows rapid evolution.
⤷ Title: From Cisco Student Rivalry to Global Hackers: Salt Typhoon Breaches 80+ Telecos for Intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #CALEA #Cisco Network Academy #Geopolitical Espionage #Qiu Daibing #Salt Typhoon #Telecommunications #Yuyang
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:10:24 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #CALEA #Cisco Network Academy #Geopolitical Espionage #Qiu Daibing #Salt Typhoon #Telecommunications #Yuyang
Daily CyberSecurity
From Cisco Student Rivalry to Global Hackers: Salt Typhoon Breaches 80+ Telecos for Intelligence
Salt Typhoon operators, former Cisco Academy students, breached 80+ telecos and CALEA systems to harvest calls from high-profile targets. The report highlights the risk of corporate tech training in geopolitics.
⤷ Title: SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:06:29 +0000
════════════════════════
⌗ Tags: #Technology #Alphabet #Elon Musk #Falcon 9 #Initial Public Offering #Investment Banking #IPO #SpaceX #Starlink #valuation
Daily CyberSecurity
SpaceX IPO: Company Prepares for 2026 Listing After Valuation Soars to $800 Billion
SpaceX is interviewing investment banks for a potential 2026 IPO after its valuation nearly doubled to $800 billion in a secondary sale, fueled by Starlink's growth.
⤷ Title: Data Disaster: Claude AI Executes rm -rf ~/ and Wipes Developer’s Mac Home Directory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:03:41 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding Assistant #Claude AI #Containerization #Data Loss #Developer Workflow #docker #Home Directory #rm _rf #security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:03:41 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding Assistant #Claude AI #Containerization #Data Loss #Developer Workflow #docker #Home Directory #rm _rf #security
Daily CyberSecurity
Data Disaster: Claude AI Executes rm -rf ~/ and Wipes Developer's Mac Home Directory
A developer's Mac home directory was wiped after Claude AI executed an unconstrained rm -rf ~/ command. Experts urge using Docker to contain AI coding tools for safety.
⤷ Title: Intel Nears SambaNova Acquisition at $1.6B Fire-Sale Price, Down from $5B Valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:00:46 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #AI chip #Generative AI #Habana Labs #intel #M&A #nvidia #RDU #SambaNova #valuation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:00:46 +0000
════════════════════════
⌗ Tags: #Technology #acquisition #AI chip #Generative AI #Habana Labs #intel #M&A #nvidia #RDU #SambaNova #valuation
Daily CyberSecurity
Intel Nears SambaNova Acquisition at $1.6B Fire-Sale Price, Down from $5B Valuation
Intel is reportedly nearing a deal to buy AI chip startup SambaNova for around $1.6B, a sharp drop from its $5B valuation, for strategic boost to its inference capabilities.
⤷ Title: API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:02:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #technology #hacking #api
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 00:02:38 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #technology #hacking #api
Medium
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.