⤷ Title: Russia’s Storm-2372 Hits Orgs with MFA Bypass via Device Code Phishing
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 18:21:48 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Phishing Scam #Cyber Attack #Cybersecurity #MFA #Phishing #Russia #Scam #SOCRadar #Storm_2372
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 18:21:48 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Phishing Scam #Cyber Attack #Cybersecurity #MFA #Phishing #Russia #Scam #SOCRadar #Storm_2372
Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Russia’s Storm-2372 Hits Orgs with MFA Bypass via Device Code Phishing
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: SaaS Security Essentials: Reducing Risks in Cloud Applications
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 18:12:03 +0000
════════════════════════
⌗ Tags: #Security #APPS #Cloud computing #Cybersecurity #SaaS #security #Technology
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 18:12:03 +0000
════════════════════════
⌗ Tags: #Security #APPS #Cloud computing #Cybersecurity #SaaS #security #Technology
Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
SaaS Security Essentials: Reducing Risks in Cloud Applications
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: BentoML Vulnerability Allows Remote Code Execution on AI Servers
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 17:14:09 +0000
════════════════════════
⌗ Tags: #Security #AI #BentoML #Checkmarx #Cybersecurity #Python #RCE #Vulnerability #WAF
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 17:14:09 +0000
════════════════════════
⌗ Tags: #Security #AI #BentoML #Checkmarx #Cybersecurity #Python #RCE #Vulnerability #WAF
Hackread
BentoML Vulnerability Allows Remote Code Execution on AI Servers
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: npm Malware Targets Atomic and Exodus Wallets to Hijack Crypto Transfers
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 20:40:30 +0000
════════════════════════
⌗ Tags: #Security #Cryptocurrency #Malware #Atomic #Crypto #Cyber Attack #Cybersecurity #Exodus #Fraud #NPM #Scam
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 10 Apr 2025 20:40:30 +0000
════════════════════════
⌗ Tags: #Security #Cryptocurrency #Malware #Atomic #Crypto #Cyber Attack #Cybersecurity #Exodus #Fraud #NPM #Scam
Hackread
npm Malware Targets Atomic and Exodus Wallets to Hijack Crypto Transfers
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: blackpill: A stealthy Linux rootkit made in Rust
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 01:30:53 +0000
════════════════════════
⌗ Tags: #Malware Offense #Linux kernel rootkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 01:30:53 +0000
════════════════════════
⌗ Tags: #Malware Offense #Linux kernel rootkit
Penetration Testing Tools
blackpill: A stealthy Linux rootkit made in Rust
blackpill is a Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs
⤷ Title: AI Exploits: A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 00:45:17 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #AI Exploits
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 00:45:17 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #AI Exploits
Penetration Testing Tools
AI Exploits: A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities
ai-exploits is a collection of exploits and scanning templates for responsibly disclosed vulnerabilities affecting machine learning tools.
⤷ Title: Obfu[DE]scate: De-obfuscation and Comparison tool for Android APKs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 00:18:52 +0000
════════════════════════
⌗ Tags: #Malware Defense #Reverse Engineering #Android #De_obfuscation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 00:18:52 +0000
════════════════════════
⌗ Tags: #Malware Defense #Reverse Engineering #Android #De_obfuscation
Penetration Testing Tools
Obfu[DE]scate: De-obfuscation and Comparison tool for Android APKs
Obfu[DE]scate is a Python tool designed to simplify the process of de-obfuscating and comparing two versions of an Android APK
⤷ Title: autotimeliner: Automagically extract forensic timeline from volatile memory dump
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 13 Apr 2025 00:07:22 +0000
════════════════════════
⌗ Tags: #Data Forensics #autotimeliner
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 13 Apr 2025 00:07:22 +0000
════════════════════════
⌗ Tags: #Data Forensics #autotimeliner
Penetration Testing Tools
autotimeliner: Automagically extract forensic timeline from volatile memory dump
autotimeliner automagically extract forensic timeline from volatile memory dumps. It Identify corrects volatility profile for the memory image.
⤷ Title: STRIDE GPT: An AI-powered threat modeling tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 13 Apr 2025 00:05:31 +0000
════════════════════════
⌗ Tags: #Data Forensics #Network Defense #AI_powered threat modeling
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 13 Apr 2025 00:05:31 +0000
════════════════════════
⌗ Tags: #Data Forensics #Network Defense #AI_powered threat modeling
Penetration Testing Tools
STRIDE GPT: An AI-powered threat modeling tool
STRIDE GPT is an AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models and attack trees
⤷ Title: EDRaser: powerful tool for remotely deleting access logs, Windows event logs, databases
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 12 Apr 2025 00:21:54 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #EDRaser
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 12 Apr 2025 00:21:54 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #EDRaser
Penetration Testing Tools
EDRaser: powerful tool for remotely deleting access logs, Windows event logs, databases
EDRaser is a powerful tool for remotely deleting access logs, Windows event logs, databases, and other files on remote machines.
⤷ Title: dot: The Deepfake Offensive Toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 12 Apr 2025 00:05:41 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #Deepfake Offensive Toolkit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 12 Apr 2025 00:05:41 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #Deepfake Offensive Toolkit
Penetration Testing Tools
dot: The Deepfake Offensive Toolkit
Deepfake Offensive Toolkit is created for performing penetration testing against e.g. identity verification and video conferencing systems
⤷ Title: wpprobe: A fast WordPress plugin enumeration tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 00:19:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 00:19:10 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Web AppSec
Penetration Testing Tools
wpprobe: A fast WordPress plugin enumeration tool
WPProbe is a fast and efficient WordPress plugin scanner that leverages REST API enumeration (?rest_route) to detect installed plugins without brute-force.
⤷ Title: Web Shell Analyzer: Web shell scanner and analyzer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 00:14:48 +0000
════════════════════════
⌗ Tags: #Forensics #Web Shell Analyzer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 00:14:48 +0000
════════════════════════
⌗ Tags: #Forensics #Web Shell Analyzer
Penetration Testing Tools
Web Shell Analyzer: Web shell scanner and analyzer
Web shell analyzer is a cross platform tool for the purpose of identifying, decoding, and tagging files that are suspected to be web shells
⤷ Title: Ghost Scheduled Task: scheduled task for both persistence and lateral movement
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 00:08:53 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #persistence #Scheduled Task
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 11 Apr 2025 00:08:53 +0000
════════════════════════
⌗ Tags: #Ethical Hacking #persistence #Scheduled Task
Penetration Testing Tools
Ghost Scheduled Task: scheduled task for both persistence and lateral movement
While using scheduled tasks as a means of persistence is not a novel approach, threat actors have employed various techniques
⤷ Title: Slow Pisces Targets Crypto Developers with Deceptive Coding Challenges
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 10:42:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #cryptocurrency #Cyber Threat #Cyberattacks #github #LinkedIn #malware #North Korea #RN Loader #RN Stealer #Slow Pisces #Unit 42
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 10:42:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #cryptocurrency #Cyber Threat #Cyberattacks #github #LinkedIn #malware #North Korea #RN Loader #RN Stealer #Slow Pisces #Unit 42
Daily CyberSecurity
Slow Pisces Targets Crypto Developers with Deceptive Coding Challenges
North Korean threat group Slow Pisces targets crypto developers with fake job offers and malicious coding challenges. Learn how they steal millions
⤷ Title: IEA Report: AI Boom Drives Massive Surge in Data Center Energy Demand
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 08:58:54 +0000
════════════════════════
⌗ Tags: #Technology #AI #artificial intelligence #climate change #data centers #electricity #energy consumption #IEA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 08:58:54 +0000
════════════════════════
⌗ Tags: #Technology #AI #artificial intelligence #climate change #data centers #electricity #energy consumption #IEA
Daily CyberSecurity
IEA Report: AI Boom Drives Massive Surge in Data Center Energy Demand
An IEA report reveals AI's growing energy demands, projecting data center electricity use to more than double by 2030, impacting global emissions targets.
⤷ Title: GPT-4 Retiring: GPT-4o Takes Over in ChatGPT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 07:25:55 +0000
════════════════════════
⌗ Tags: #Technology #AI models #AI retirement #artificial intelligence #ChatGPT #GPT_4 #GPT_4o #language models #OpenAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 07:25:55 +0000
════════════════════════
⌗ Tags: #Technology #AI models #AI retirement #artificial intelligence #ChatGPT #GPT_4 #GPT_4o #language models #OpenAI
Daily CyberSecurity
GPT-4 Retiring: GPT-4o Takes Over in ChatGPT
GPT-4 retires in ChatGPT as OpenAI shifts to GPT-4o, offering enhanced multimodal capabilities. Developers retain GPT-4 API access.
⤷ Title: Fortinet Uncovers Threat Actor Persistence via Symbolic Link Exploit in FortiGate Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 04:42:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2022_42475 #CVE_2023_27997 #CVE_2024_21762 #cybersecurity #FortiGate #Fortinet #patch management #SSL_VPN vulnerability #symbolic link
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 04:42:42 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2022_42475 #CVE_2023_27997 #CVE_2024_21762 #cybersecurity #FortiGate #Fortinet #patch management #SSL_VPN vulnerability #symbolic link
Daily CyberSecurity
Fortinet Uncovers Threat Actor Persistence via Symbolic Link Exploit in FortiGate Devices
Fortinet warns of a novel persistence exploit using symbolic links in FortiGate SSL-VPNs. Upgrade to patched FortiOS versions to mitigate the threat.
⤷ Title: SSL Certificate Validity Reduced to 47 Days After Apple Proposal
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 04:12:19 +0000
════════════════════════
⌗ Tags: #Technology #Apple #CA/Browser Forum #certificates #cybersecurity #ssl #tls #Web Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 04:12:19 +0000
════════════════════════
⌗ Tags: #Technology #Apple #CA/Browser Forum #certificates #cybersecurity #ssl #tls #Web Security
Daily CyberSecurity
SSL Certificate Validity Reduced to 47 Days After Apple Proposal
SSL certificate validity to drop to 47 days after Apple's proposal, impacting web security and increasing renewal frequency for enterprises.
⤷ Title: OpenAI to Require ID Verification for Advanced AI Models
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 03:40:06 +0000
════════════════════════
⌗ Tags: #Technology #AI models #API #Developers #GPT #identity verification #OpenAI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Apr 2025 03:40:06 +0000
════════════════════════
⌗ Tags: #Technology #AI models #API #Developers #GPT #identity verification #OpenAI
Daily CyberSecurity
OpenAI to Require ID Verification for Advanced AI Models
OpenAI plans to introduce ID verification for API accounts to combat misuse, granting access to advanced AI models only to verified users.