⤷ Title: From Stealer to Spy: AMOS Malware Evolves into Full-Fledged Backdoor Threat for macOS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:32:17 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Apple #backdoor #cybersecurity #infosec #macOS #malware #persistence #stealer #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:32:17 +0000
════════════════════════
⌗ Tags: #Malware #AMOS #Apple #backdoor #cybersecurity #infosec #macOS #malware #persistence #stealer #threat intelligence
Daily CyberSecurity
From Stealer to Spy: AMOS Malware Evolves into Full-Fledged Backdoor Threat for macOS
AMOS malware just leveled up—now a backdoor, it poses a serious threat to macOS with persistent access and remote command execution.
⤷ Title: Opossum Attack: New Vulnerability Compromises Encrypted TLS Connections, Allowing MitM & Data Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:26:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Desynchronization #FTP #http #Man in the Middle #mitm #Opossum Attack #Opportunistic TLS #SMTP #tls #Transport Layer Security #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:26:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Desynchronization #FTP #http #Man in the Middle #mitm #Opossum Attack #Opportunistic TLS #SMTP #tls #Transport Layer Security #Vulnerability
Daily CyberSecurity
Opossum Attack: New Vulnerability Compromises Encrypted TLS Connections, Allowing MitM & Data Injection
The Opossum Attack is a new desynchronization flaw exploiting implicit/opportunistic TLS in protocols like HTTP, allowing MitM to compromise encrypted connections. Over 3M servers affected.
⤷ Title: Critical Vulnerabilities Found in Schneider Electric’s EcoStruxure IT Data Center Expert
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:21:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #cybersecurity #DCE #EcoStruxure IT Data Center Expert #privilege escalation #rce #Remote Code Execution #Schneider Electric #ssrf #Vulnerability #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:21:21 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #cybersecurity #DCE #EcoStruxure IT Data Center Expert #privilege escalation #rce #Remote Code Execution #Schneider Electric #ssrf #Vulnerability #xxe
Daily CyberSecurity
Critical Vulnerabilities Found in Schneider Electric’s EcoStruxure IT Data Center Expert
Schneider Electric warns of critical flaws (CVSS 10.0 RCE, SSRF, EoP) in EcoStruxure IT Data Center Expert. Patch to v9.0 immediately to prevent data center disruption.
⤷ Title: OFAC Sanctions Key Players in North Korea’s Remote IT Worker Scheme Funding Weapons Programs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:18:37 +0000
════════════════════════
⌗ Tags: #Cyber Security #Andariel #cyber_espionage #Cybercrime #DPRK #Gayk Asatryan #North Korea #OFAC #Remote IT Workers #Revenue Generation #RGB #sanctions #Song Kum Hyok #Treasury
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:18:37 +0000
════════════════════════
⌗ Tags: #Cyber Security #Andariel #cyber_espionage #Cybercrime #DPRK #Gayk Asatryan #North Korea #OFAC #Remote IT Workers #Revenue Generation #RGB #sanctions #Song Kum Hyok #Treasury
Daily CyberSecurity
OFAC Sanctions Key Players in North Korea's Remote IT Worker Scheme Funding Weapons Programs
OFAC sanctioned Song Kum Hyok (Andariel) and others for orchestrating North Korea's remote IT worker scheme, which used stolen identities to fund DPRK weapons programs.
⤷ Title: Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
Daily CyberSecurity
Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
GeoServer's RCE flaw (CVE-2024-36401) is actively exploited to deploy NetCat reverse shells and XMRig CoinMiners on Windows/Linux, hijacking resources.
⤷ Title: CISA Warns of Critical Flaws in Emerson ValveLink Software: Exploits Could Lead to Code Execution and Data Exposure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:08:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Cleartext Data #Code Execution #CVE_2025_46358 #CVE_2025_48496 #CVE_2025_50109 #CVE_2025_52579 #CVE_2025_53471 #cybersecurity #Emerson #ICS #industrial control systems #SCADA #ValveLink #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:08:38 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Cleartext Data #Code Execution #CVE_2025_46358 #CVE_2025_48496 #CVE_2025_50109 #CVE_2025_52579 #CVE_2025_53471 #cybersecurity #Emerson #ICS #industrial control systems #SCADA #ValveLink #Vulnerability
Daily CyberSecurity
CISA Warns of Critical Flaws in Emerson ValveLink Software: Exploits Could Lead to Code Execution and Data Exposure
CISA warns of critical flaws in Emerson ValveLink software, exposing cleartext data, allowing code execution, and compromising industrial systems. Update to v14.0 now.
⤷ Title: Gold Melody’s Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:00:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ASP.NET #cybersecurity #GodPotato #Gold Melody #IAB #initial access broker #Machine Key #Palo Alto Networks #privilege escalation #rce #Remote Code Execution #UNC961 #View State Deserialization
Daily CyberSecurity
Gold Melody's Stealthy Campaign: Leaked ASP.NET Machine Keys Fuel In-Memory RCE & Privilege Escalation
Unit 42 reveals "Gold Melody" uses leaked ASP.NET Machine Keys to achieve in-memory RCE via View State deserialization and privilege escalation via GodPotato, compromising web servers.
⤷ Title: The 16B records Data Breach that did not exist
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:19:21 GMT
════════════════════════
⌗ Tags: #company #data_breach #bug_bounty #news #cybersecurity
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:19:21 GMT
════════════════════════
⌗ Tags: #company #data_breach #bug_bounty #news #cybersecurity
Medium
The 16B records Data Breach that did not exist
A wave of news recently swept social media and the news, claiming that “Apple, Google, Facebook, Telegram, GitHub passwords leaked in…
⤷ Title: How I Tricked a Fellow Airman, and What It Taught Me About “Authority” in Social Engineering
════════════════════════
𐀪 Author: JD Brooks
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:51:10 GMT
════════════════════════
⌗ Tags: #military #infosec #social_engineering #veterans #cybersecurity_awareness
════════════════════════
𐀪 Author: JD Brooks
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:51:10 GMT
════════════════════════
⌗ Tags: #military #infosec #social_engineering #veterans #cybersecurity_awareness
Medium
How I Tricked a Fellow Airman, and What It Taught Me About “Authority” in Social Engineering
In the military, you pretty much just do what you’re told. With rare exceptions (e.g., an unlawful order), one might snap back at a…
⤷ Title: The Cloud Explained (Like I’m 5)
════════════════════════
𐀪 Author: TechTales
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:09:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #cloud_computing #education_technology #technology #cloud
════════════════════════
𐀪 Author: TechTales
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:09:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #cloud_computing #education_technology #technology #cloud
Medium
The Cloud Explained (Like I’m 5)
In an ever-evolving world filled with new ideas and innovations, a common term we often hear is the “cloud.”
⤷ Title: CVE-2025–52367: Stored XSS to RCE via Privilege Escalation in PivotX CMS v3.0.0 RC 3
════════════════════════
𐀪 Author: HayToN
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:07:39 GMT
════════════════════════
⌗ Tags: #researching #cms #xss_attack #cybersecurity #rce_vulnerability
════════════════════════
𐀪 Author: HayToN
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:07:39 GMT
════════════════════════
⌗ Tags: #researching #cms #xss_attack #cybersecurity #rce_vulnerability
Medium
CVE-2025–52367: Stored XSS to RCE via Privilege Escalation in PivotX CMS v3.0.0 RC 3
Author: HayToN Date: July 2025 CVE ID: CVE-2025–52367 Vulnerability Type: Stored Cross-Site Scripting (XSS) To RCE (Remote Command…
⤷ Title: Fortinet FortiManager: A Comprehensive Guide
════════════════════════
𐀪 Author: Juara IT Solutions
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:31:42 GMT
════════════════════════
⌗ Tags: #data_security #fortinet #cloud_security #network_security #cybersecurity
════════════════════════
𐀪 Author: Juara IT Solutions
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:31:42 GMT
════════════════════════
⌗ Tags: #data_security #fortinet #cloud_security #network_security #cybersecurity
Medium
Fortinet FortiManager: A Comprehensive Guide
Fortinet FortiManager is a centralized security management solution that empowers enterprises and service providers to control thousands of…
⤷ Title: IA for Security — Memória em Chatbots LLMs: Short e Long Memory na Prática — Parte 2
════════════════════════
𐀪 Author: Fernando Carrara
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:17:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence
════════════════════════
𐀪 Author: Fernando Carrara
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:17:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence
Medium
IA for Security — Memória em Chatbots LLMs: Short e Long Memory na Prática — Parte 2
Na primeira parte deste projeto, construímos um chatbot baseado em LLM com execução do modelo local, utilizando o Langflow e o modelo LLaMA 2 7B Chat. Passei pelos conceitos iniciais de…
⤷ Title: ContAInment . TryHackMe Walkthrough . AI/ML DFIR
════════════════════════
𐀪 Author: RosanaFSS
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:00:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_walkthrough #tryhackme #ethical_hacking #artificial_intelligence
════════════════════════
𐀪 Author: RosanaFSS
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:00:29 GMT
════════════════════════
⌗ Tags: #cybersecurity #tryhackme_walkthrough #tryhackme #ethical_hacking #artificial_intelligence
Medium
ContAInment . TryHackMe Walkthrough . AI/ML DFIR
Defensive AI → ContAInment → 5 of 5. Can you help contain the ransomware threat with the help of AI?
⤷ Title: Evil-GPT: Write-Up
════════════════════════
𐀪 Author: A Learner
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:48:47 GMT
════════════════════════
⌗ Tags: #penetration_testing #ai #llm #tryhackme #writeup
════════════════════════
𐀪 Author: A Learner
════════════════════════
ⴵ Time: Wed, 09 Jul 2025 23:48:47 GMT
════════════════════════
⌗ Tags: #penetration_testing #ai #llm #tryhackme #writeup
Medium
Evil-GPT: Write-Up
A write-up for LLM security based TryHackMe room. We exploit AI agent to execute commands and go beyond retrieving flag for some fun stuff!
⤷ Title: The Easiest Bug Bounty you’ll ever get (2025)
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:02:06 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #computer_security #hacking #computer_science
════════════════════════
𐀪 Author: Appsec.pt
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:02:06 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #computer_security #hacking #computer_science
Medium
The Easiest Bug Bounty you’ll ever get (2025)
The most overlooked bug in 2025. Learn the easiest way to get bounties and help secure companies.
⤷ Title: Interview with Lewis: Inside the Underground Mail-Order Drug Trade
════════════════════════
𐀪 Author: Internet Exposed
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 02:43:29 GMT
════════════════════════
⌗ Tags: #drugs #mail #america #scam #cybersecurity
════════════════════════
𐀪 Author: Internet Exposed
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 02:43:29 GMT
════════════════════════
⌗ Tags: #drugs #mail #america #scam #cybersecurity
Medium
Interview with Lewis: Inside the Underground Mail-Order Drug Trade
The following is a transcript of a conversation with “Lewis” (not his real name), a former mail-based drug distributor who worked full-time…
⤷ Title: Warning to ServiceNow Admins: Misconfigured ACLs Could Lead to Serious Data Leaks
════════════════════════
𐀪 Author: Darshan
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 02:34:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #services #servicenow #vulnerability
════════════════════════
𐀪 Author: Darshan
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 02:34:41 GMT
════════════════════════
⌗ Tags: #cybersecurity #technology #services #servicenow #vulnerability
Medium
Warning to ServiceNow Admins: Misconfigured ACLs Could Lead to Serious Data Leaks
A newly revealed vulnerability in ServiceNow’s Access Control Lists (ACLs) could let attackers — both unauthenticated and authenticated —…
⤷ Title: Armazenamento seguro de credenciais no Terraform com 'blocos efêmeros' e atributos 'somente…
════════════════════════
𐀪 Author: ISHII (石井)
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:58:52 GMT
════════════════════════
⌗ Tags: #terraform #devops #cybersecurity #infrastructure #infrastructure_as_code
════════════════════════
𐀪 Author: ISHII (石井)
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:58:52 GMT
════════════════════════
⌗ Tags: #terraform #devops #cybersecurity #infrastructure #infrastructure_as_code
Medium
Armazenamento seguro de credenciais no Terraform com 'blocos efêmeros' e atributos 'somente escrita'
HashiCorp Terraform
⤷ Title: How to Fix the “NO_PUBKEY” Error in Kali Linux
════════════════════════
𐀪 Author: Uzoukwu Eric Ikenna
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:57:20 GMT
════════════════════════
⌗ Tags: #package_management #gpg_key #linux #cybersecurity #linux_troubleshooting
════════════════════════
𐀪 Author: Uzoukwu Eric Ikenna
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 01:57:20 GMT
════════════════════════
⌗ Tags: #package_management #gpg_key #linux #cybersecurity #linux_troubleshooting
Medium
How to Fix the “NO_PUBKEY” Error in Kali Linux
Resolve GPG key issues in Kali Linux and keep your system secure and up to date.