⤷ Title: Silent Saboteurs: How AI Could Learn, Lurk, and Dismantle Entire Organizations from Within
════════════════════════
𐀪 Author: Jeffrey Nickle
════════════════════════
ⴵ Time: Tue, 08 Apr 2025 23:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #threat_intelligence #security #enterprise_security
════════════════════════
𐀪 Author: Jeffrey Nickle
════════════════════════
ⴵ Time: Tue, 08 Apr 2025 23:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #threat_intelligence #security #enterprise_security
Medium
Silent Saboteurs: How AI Could Learn, Lurk, and Dismantle Entire Organizations from Within
While AI’s offensive capabilities in misinformation and automation have taken center stage, its potential for long-term logical path…
⤷ Title: Rebound HackTheBox | Detailed Writeup
════════════════════════
𐀪 Author: 0xleksa
════════════════════════
ⴵ Time: Tue, 08 Apr 2025 23:42:57 GMT
════════════════════════
⌗ Tags: #active_directory #windows #penetration_testing #security #hackthebox
════════════════════════
𐀪 Author: 0xleksa
════════════════════════
ⴵ Time: Tue, 08 Apr 2025 23:42:57 GMT
════════════════════════
⌗ Tags: #active_directory #windows #penetration_testing #security #hackthebox
Medium
Rebound HackTheBox | Detailed Writeup
Absolute monster. One of the greatest machines out there on the platform. The machine consists of RID search, AS-REP Roasting…
⤷ Title: OdinLdr: Cobaltstrike Reflective Loader with Synthetic Stackframe
════════════════════════
𐀪 Author: ddos-admin
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:53:19 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #Cobaltstrike Reflective Loader #OdinLdr
════════════════════════
𐀪 Author: ddos-admin
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:53:19 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #Cobaltstrike Reflective Loader #OdinLdr
Penetration Testing Tools
OdinLdr: Cobaltstrike Reflective Loader with Synthetic Stackframe
Cobaltstrike UDRL for beacon and post-ex tools. Use NtApi call with synthetic stackframe to confuse EDR based on stackframe detection.
⤷ Title: pcfg_cracker: perform research into how humans generate passwords
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:24:17 +0000
════════════════════════
⌗ Tags: #Ethical Hacking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:24:17 +0000
════════════════════════
⌗ Tags: #Ethical Hacking
Penetration Testing Tools
pcfg_cracker: perform research into how humans generate passwords
A collection of tools to perform research into how humans generate passwords. These can be used to crack password hashes
⤷ Title: sherloq: open-source digital image forensic toolset
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:20:28 +0000
════════════════════════
⌗ Tags: #Data Forensics #digital image forensic #sherloq
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:20:28 +0000
════════════════════════
⌗ Tags: #Data Forensics #digital image forensic #sherloq
Penetration Testing Tools
sherloq: open-source digital image forensic toolset
Sherloq is a personal research project about implementing a fully integrated environment for digital image forensic.
⤷ Title: Windows CLFS Zero-Day Exploited to Deploy Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 01:34:21 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CLFS #CVE_2025_29824 #cybersecurity #Microsoft #PipeMagic #privilege escalation #ransomware #Storm_2460 #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 01:34:21 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #CLFS #CVE_2025_29824 #cybersecurity #Microsoft #PipeMagic #privilege escalation #ransomware #Storm_2460 #zero_day
Daily CyberSecurity
Windows CLFS Zero-Day Exploited to Deploy Ransomware
Microsoft reports active exploitation of a Windows CLFS zero-day (CVE-2025-29824) to escalate privileges and deploy ransomware. Learn about the attacks, the threat actors involved, and how to mitigate the risk.
⤷ Title: Siemens Security Alert: Critical Vulnerabilities in SENTRON 7KT PAC1260 Data Manager
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 01:00:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CSRF #CVE_2024_41788 #industrial control systems #Remote Code Execution #security advisory #SENTRON 7KT PAC1260 #Siemens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 01:00:50 +0000
════════════════════════
⌗ Tags: #Vulnerability #Authentication Bypass #CSRF #CVE_2024_41788 #industrial control systems #Remote Code Execution #security advisory #SENTRON 7KT PAC1260 #Siemens
Daily CyberSecurity
Siemens Security Alert: Critical Vulnerabilities in SENTRON 7KT PAC1260 Data Manager
Siemens ProductCERT issued a security advisory detailing critical vulnerabilities in the SENTRON 7KT PAC1260 Data Manager. The flaws could allow remote attackers to execute code, bypass authentication, and more.
⤷ Title: Kibana Code Injection Vulnerability: Prototype Pollution Threat (CVE-2024-12556)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:52:27 +0000
════════════════════════
⌗ Tags: #Vulnerability #code_injection #CVE_2024_12556 #Elasticsearch #file upload #Kibana #Path Traversal #Prototype Pollution #security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:52:27 +0000
════════════════════════
⌗ Tags: #Vulnerability #code_injection #CVE_2024_12556 #Elasticsearch #file upload #Kibana #Path Traversal #Prototype Pollution #security
Daily CyberSecurity
Kibana Code Injection Vulnerability: Prototype Pollution Threat (CVE-2024-12556)
A vulnerability (CVE-2024-12556) in Kibana allows code injection via prototype pollution, file upload, and path traversal. Upgrade to the latest version or disable the integration assistant to mitigate this high-severity security risk.
⤷ Title: Neptune RAT: Advanced Malware Targets Windows with Destructive Capabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:44:24 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cyber Threat #cybersecurity #Data Theft #malware #Neptune RAT #ransomware #Remote Access Trojan #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:44:24 +0000
════════════════════════
⌗ Tags: #Malware #anti_analysis #Cyber Threat #cybersecurity #Data Theft #malware #Neptune RAT #ransomware #Remote Access Trojan #windows
Daily CyberSecurity
Neptune RAT: Advanced Malware Targets Windows with Destructive Capabilities
CYFIRMA researchers discovered Neptune RAT, an advanced Remote Access Trojan targeting Windows. Learn about its destructive features, evasion techniques, and distribution methods.
⤷ Title: Chrome Update Fixes High-Severity “Use After Free” Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #browser #chrome #CVE_2025_3066 #security #Site Isolation #update #use after free
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:42:31 +0000
════════════════════════
⌗ Tags: #Vulnerability #browser #chrome #CVE_2025_3066 #security #Site Isolation #update #use after free
Daily CyberSecurity
Chrome Update Fixes High-Severity "Use After Free" Vulnerability
The latest Chrome update addresses a high-severity "use after free" vulnerability in Site Isolation (CVE-2025-3066). Learn about the security risk and the importance of updating your Chrome browser
⤷ Title: Rogue RDP: Abusing RDP for File Theft and Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:40:18 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybersecurity #file theft #phishing attack #PyRDP #RDP #RemoteApp #resource redirection #UNC5837
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:40:18 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybersecurity #file theft #phishing attack #PyRDP #RDP #RemoteApp #resource redirection #UNC5837
Daily CyberSecurity
Rogue RDP: Abusing RDP for File Theft and Espionage
Attackers are using "Rogue RDP" techniques, abusing RemoteApp and resource redirection to steal files and conduct espionage
⤷ Title: Microsoft April 2025 Patch Tuesday: Critical Security Updates and Zero-Day Exploits
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:36:00 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #CVE_2025_29824 #cybersecurity #Microsoft #Patch Tuesday #rce #Remote Code Execution #security update #windows #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:36:00 +0000
════════════════════════
⌗ Tags: #Vulnerability #Windows #CVE_2025_29824 #cybersecurity #Microsoft #Patch Tuesday #rce #Remote Code Execution #security update #windows #zero_day
Daily CyberSecurity
Microsoft April 2025 Patch Tuesday: Critical Security Updates and Zero-Day Exploits
Microsoft's April 2025 Patch Tuesday addresses 134 vulnerabilities, including a zero-day under active exploitation. This update covers critical RCE flaws in Windows, Office, and more
⤷ Title: Inaba Denki Sangyo Wi-Fi AP Units Affected by Critical Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:30:03 +0000
════════════════════════
⌗ Tags: #Vulnerability #access point #Authentication Bypass #Command Injection #CVE_2025_25053 #CVE_2025_27797 #Inaba Denki Sangyo #security vulnerability #Wi_Fi #Wi_Fi vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:30:03 +0000
════════════════════════
⌗ Tags: #Vulnerability #access point #Authentication Bypass #Command Injection #CVE_2025_25053 #CVE_2025_27797 #Inaba Denki Sangyo #security vulnerability #Wi_Fi #Wi_Fi vulnerability
Daily CyberSecurity
Inaba Denki Sangyo Wi-Fi AP Units Affected by Critical Vulnerabilities
JPCERT/CC reports multiple vulnerabilities in Inaba Denki Sangyo Wi-Fi AP units, including command injection and authentication issues
⤷ Title: Vidar Stealer Hides in Legitimate BGInfo Tool
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:25:43 +0000
════════════════════════
⌗ Tags: #Malware #BGInfo #cybersecurity #information stealer #malware #threat analysis #Vidar Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:25:43 +0000
════════════════════════
⌗ Tags: #Malware #BGInfo #cybersecurity #information stealer #malware #threat analysis #Vidar Stealer
Daily CyberSecurity
Vidar Stealer Hides in Legitimate BGInfo Tool
Vidar Stealer malware is distributed by masquerading as BGInfo.exe, exploiting expired signatures and file discrepancies to evade detection
⤷ Title: SourceForge Used to Distribute ClipBanker Trojan and Cryptocurrency Miner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:24:47 +0000
════════════════════════
⌗ Tags: #Malware #ClipBanker #cryptocurrency #cyberattack #malware #security #SourceForge #Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:24:47 +0000
════════════════════════
⌗ Tags: #Malware #ClipBanker #cryptocurrency #cyberattack #malware #security #SourceForge #Trojan
Daily CyberSecurity
SourceForge Used to Distribute ClipBanker Trojan and Cryptocurrency Miner
Attackers are using SourceForge to distribute malware, including a ClipBanker Trojan and a cryptocurrency miner, disguised as a Microsoft Office enhancement suite.
⤷ Title: Grandoreiro Trojan Resurges in Phishing Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:20:15 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Acrobat Reader #banking #Banking Trojan #cybersecurity #Europe #Grandoreiro #Latin America #malware #phishing #Trojan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:20:15 +0000
════════════════════════
⌗ Tags: #Malware #Adobe Acrobat Reader #banking #Banking Trojan #cybersecurity #Europe #Grandoreiro #Latin America #malware #phishing #Trojan
Daily CyberSecurity
Grandoreiro Trojan Resurges in Phishing Attacks
The Grandoreiro banking trojan is being spread through phishing campaigns. Learn about the attack methods and how to stay safe.
⤷ Title: Apache mod_auth_openidc Vulnerability Exposes Protected Content
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:10:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache #Apache security #authentication #CVE_2025_31492 #cybersecurity #mod_auth_openidc #OpenID Connect #security advisory
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:10:44 +0000
════════════════════════
⌗ Tags: #Vulnerability #apache #Apache security #authentication #CVE_2025_31492 #cybersecurity #mod_auth_openidc #OpenID Connect #security advisory
Daily CyberSecurity
Apache mod_auth_openidc Vulnerability Exposes Protected Content
A security flaw in Apache's mod_auth_openidc module can expose protected web content to unauthenticated users. Patch or mitigate to secure your server
⤷ Title: Malicious VSCode Extensions Caught Mining Crypto with XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:05:58 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #OnedriveStartup #VSCode extensions #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:05:58 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #OnedriveStartup #VSCode extensions #XMRig
Daily CyberSecurity
Malicious VSCode Extensions Caught Mining Crypto with XMRig
Ten popular Visual Studio Code extensions were found secretly installing XMRig miners, exploiting users’ CPUs for unauthorized cryptomining.
⤷ Title: Account Manipulation Lead to Anonymous Account existence
════════════════════════
𐀪 Author: Ziademad
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 01:18:33 GMT
════════════════════════
⌗ Tags: #bug_bounty #account_take_over #bug_bounty_writeup
════════════════════════
𐀪 Author: Ziademad
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 01:18:33 GMT
════════════════════════
⌗ Tags: #bug_bounty #account_take_over #bug_bounty_writeup
Medium
Account Manipulation Lead to Anonymous Account existence
السلام عليكم ورحمة الله وبركاته .,,
⤷ Title: Bug Bounty Journey — Valid Report Part 5
════════════════════════
𐀪 Author: 0xF3r4t
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:45:00 GMT
════════════════════════
⌗ Tags: #misconfiguration #bug_bounty #email_verification_bypass #aws_cognito #vdp
════════════════════════
𐀪 Author: 0xF3r4t
════════════════════════
ⴵ Time: Wed, 09 Apr 2025 00:45:00 GMT
════════════════════════
⌗ Tags: #misconfiguration #bug_bounty #email_verification_bypass #aws_cognito #vdp
Medium
Bug Bounty Journey — Valid Report Part 5
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…