⤷ Title: Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:04:57 +0000
════════════════════════
⌗ Tags: #Malware #cryptomining #defense evasion #LOLBins #persistence #Tangerine Turkey #USB malware #VBScript Worm #XMRig
Daily CyberSecurity
Tangerine Turkey Cryptomining Worm Spreads Via USB Drives, Hides Payloads with VBScript and LOLBins
Cybereason exposed Tangerine Turkey, a VBScript worm that spreads via USB drives. It uses LOLBins (printui.exe) and Windows Defender exclusions to deploy the XMRig cryptominer for profit.
⤷ Title: Copyright Pivot: Getty Images Partners with Perplexity AI to Tackle Content Attribution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:36 +0000
════════════════════════
⌗ Tags: #Technology #AI Search #Attribution #content #copyright #Getty Images #Lawsuit #Licensing #Perplexity.ai
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:36 +0000
════════════════════════
⌗ Tags: #Technology #AI Search #Attribution #content #copyright #Getty Images #Lawsuit #Licensing #Perplexity.ai
Daily CyberSecurity
Copyright Pivot: Getty Images Partners with Perplexity AI to Tackle Content Attribution
Perplexity AI licenses Getty Images' visual archives to integrate visuals into search with proper attribution, marking a strategic shift in AI copyright battles.
⤷ Title: Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:00:22 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Bypass #CVE_2025_37736 #ECE #Elastic #Improper Authorization #privilege escalation #Readonly User
Daily CyberSecurity
Elastic Patches High-Severity Privilege Escalation Flaw in Elastic Cloud Enterprise (CVE-2025-37736)
Elastic patched a Critical EoP flaw (CVE-2025-37736) in ECE (v3.8.3/4.0.3) where the readonly user can create admin users and inject new API keys by bypassing authorization checks.
⤷ Title: Testing XSS in chatbot instances
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 23:54:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_attack
════════════════════════
𐀪 Author: 4osp3l
════════════════════════
ⴵ Time: Sun, 02 Nov 2025 23:54:23 GMT
════════════════════════
⌗ Tags: #bug_bounty #xss_attack
Medium
Testing XSS in chatbot instances
Here’s a little tip for testing XSS in chatbot instances; when you inject an XSS payload as a user message and it doesn’t execute, don’t…
⤷ Title: The Digital Hoarder’s Dilemma: Why Your Backup Strategy Is Probably Broken (And How to Fix It)
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:14:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #programming #technology #privacy #hacking
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:14:35 GMT
════════════════════════
⌗ Tags: #cybersecurity #programming #technology #privacy #hacking
Medium
The Digital Hoarder’s Dilemma: Why Your Backup Strategy Is Probably Broken (And How to Fix It)
A brutally honest look at why we’re all terrible at protecting our digital lives
⤷ Title: The Delicate and Destructive Art of the Side Project Graveyard
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:18:56 GMT
════════════════════════
⌗ Tags: #productivity #hacking #coding #side_project #technology
════════════════════════
𐀪 Author: Aeon Flex, Elriel Assoc. 2133 [NEON MAXIMA]
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:18:56 GMT
════════════════════════
⌗ Tags: #productivity #hacking #coding #side_project #technology
Medium
The Delicate and Destructive Art of the Side Project Graveyard
Nothing wrong with adding a few more bodies to the pile.
⤷ Title: Invisible Entry Points: Why DNS, Ports, and IP Hygiene Define Web Security
════════════════════════
𐀪 Author: Cybamatica
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:36:18 GMT
════════════════════════
⌗ Tags: #network_security #dns #infosec #cybersecurity #web_security
════════════════════════
𐀪 Author: Cybamatica
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:36:18 GMT
════════════════════════
⌗ Tags: #network_security #dns #infosec #cybersecurity #web_security
Medium
Invisible Entry Points: Why DNS, Ports, and IP Hygiene Define Web Security
When securing a website, many focus on the obvious security aspects such as HTTPS, regular updates, and reputable hosting providers. But…
⤷ Title: PortSwigger Labs: Server Side Request Forgery (SSRF) Writeup (ALL LABS)
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:56:41 GMT
════════════════════════
⌗ Tags: #burpsuite #penetration_testing #portswigger #web_application_security #cybersecurity
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:56:41 GMT
════════════════════════
⌗ Tags: #burpsuite #penetration_testing #portswigger #web_application_security #cybersecurity
Medium
PortSwigger Labs: Server Side Request Forgery (SSRF) Writeup (ALL LABS)
I. SSRF with blacklist-based input filter
⤷ Title: PortSwigger Labs: Prototype Pollution Writeup (All labs)
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:48:31 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_application_security #portswigger #cybersecurity #burpsuite
════════════════════════
𐀪 Author: awes0meness
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:48:31 GMT
════════════════════════
⌗ Tags: #penetration_testing #web_application_security #portswigger #cybersecurity #burpsuite
Medium
PortSwigger Labs: Prototype Pollution Writeup (All labs)
I. DOM XSS via client-side prototype pollution
⤷ Title: Ini Cara Gampang Bikin Sistem Jebol!
════════════════════════
𐀪 Author: Jadi Hacker
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:37:57 GMT
════════════════════════
⌗ Tags: #owasp #websecurity_testing #cybersecurity #penetration_testing #broken_access_control
════════════════════════
𐀪 Author: Jadi Hacker
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 01:37:57 GMT
════════════════════════
⌗ Tags: #owasp #websecurity_testing #cybersecurity #penetration_testing #broken_access_control
Medium
Ini Cara Gampang Bikin Sistem Jebol!
Untuk kalian yang ngaku pengen jadi hacker, pernah dengar istilah BAC atau Broken Access Control?
⤷ Title: From Chapter 13 Trustee Court Attendant to Beauty Boss: How I Built the American Dream (Before It…
════════════════════════
𐀪 Author: Krystal
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:33:50 GMT
════════════════════════
⌗ Tags: #business #this_happened_to_me #beauty #cybersecurity #entrepreneurship
════════════════════════
𐀪 Author: Krystal
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:33:50 GMT
════════════════════════
⌗ Tags: #business #this_happened_to_me #beauty #cybersecurity #entrepreneurship
Medium
From Chapter 13 Trustee Court Attendant to Beauty Boss: How I Built the American Dream (Before It…
From Chapter 13 Trustee Court Attendant to Beauty Boss: How I Built the American Dream (Before It Was Stolen) Part One: The Beginning - When Dreams Were Still Safe By Krystal N. Pereyra, Licensed …
⤷ Title: Inside OAuth 2.0: The Four Roles Powering Every ‘Sign in with Google
════════════════════════
𐀪 Author: Himanshu Soni
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:55 GMT
════════════════════════
⌗ Tags: #software_development #data_science #artificial_intelligence #cybersecurity #software_engineering
════════════════════════
𐀪 Author: Himanshu Soni
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:55 GMT
════════════════════════
⌗ Tags: #software_development #data_science #artificial_intelligence #cybersecurity #software_engineering
Medium
Inside OAuth 2.0: The Four Roles Powering Every ‘Sign in with Google
When I first started building web apps that needed to connect with third-party APIs Google, GitHub, Twitter I thought all I needed was an…
⤷ Title: Threat Intelligence Fundamentals: Turning Data Into Defense
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:55 GMT
════════════════════════
⌗ Tags: #information_security #threat_intelligence #women_in_tech #cybersecurity
════════════════════════
𐀪 Author: Cybersecurity Simplified
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:55 GMT
════════════════════════
⌗ Tags: #information_security #threat_intelligence #women_in_tech #cybersecurity
Medium
Threat Intelligence Fundamentals: Turning Data Into Defense
Threat intelligence isn’t just collecting IOCs from Twitter feeds. It’s about transforming raw data into actionable insights that guide…
⤷ Title: Blue Team Labs Online | Memory Analysis — Ransomware | Walkthrough
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:55 GMT
════════════════════════
⌗ Tags: #blueteamlabs #btlo #blueteamlabsonline #blue_team #cybersecurity
════════════════════════
𐀪 Author: Drew Arpino
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 00:01:55 GMT
════════════════════════
⌗ Tags: #blueteamlabs #btlo #blueteamlabsonline #blue_team #cybersecurity
Medium
Blue Team Labs Online | Memory Analysis — Ransomware | Walkthrough
A Memory Analysis Challenge Using Volatility 2.6.
⤷ Title: Finally: Windows 11 Tests Shared Bluetooth Audio on Two Devices, Starting with Copilot+ PCs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:58:45 +0000
════════════════════════
⌗ Tags: #Windows #Bluetooth #Copilot #LE Audio #Microsoft #Shared Audio #Snapdragon #Surface #Windows 11
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:58:45 +0000
════════════════════════
⌗ Tags: #Windows #Bluetooth #Copilot #LE Audio #Microsoft #Shared Audio #Snapdragon #Surface #Windows 11
Penetration Testing Tools
Finally: Windows 11 Tests Shared Bluetooth Audio on Two Devices, Starting with Copilot+ PCs
Microsoft began testing Shared Audio for Windows 11 (Build 26220.7051), enabling simultaneous playback on two Bluetooth devices. Feature is currently limited to Copilot+ PCs.
⤷ Title: Qilin Ransomware Claims Hack on Japan’s Super Value Supermarket, Leaks Payroll & P&L Data
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:57:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #Dark Web #data breach #Japan #Payroll #Qilin #ransomware #Retail #Super Value
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:57:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybercrime #Dark Web #data breach #Japan #Payroll #Qilin #ransomware #Retail #Super Value
Penetration Testing Tools
Qilin Ransomware Claims Hack on Japan’s Super Value Supermarket, Leaks Payroll & P&L Data
Qilin ransomware claims a massive data breach against Japan’s Super Value supermarket chain, leaking payroll, sales, and sensitive employee PII on the dark web.
⤷ Title: Instant Block: Microsoft Edge Gains New Sensor for Faster Scareware Scam Protection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:55:01 +0000
════════════════════════
⌗ Tags: #Malware #Microsoft #browser security #Defender SmartScreen #Edge 142 #microsoft edge #phishing #Scareware #Tech Support Scam
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:55:01 +0000
════════════════════════
⌗ Tags: #Malware #Microsoft #browser security #Defender SmartScreen #Edge 142 #microsoft edge #phishing #Scareware #Tech Support Scam
Penetration Testing Tools
Instant Block: Microsoft Edge Gains New Sensor for Faster Scareware Scam Protection
Microsoft Edge introduces a new sensor using machine learning to instantly detect and block scareware and tech support scams, avoiding fake system virus alerts.
⤷ Title: Cisco Router Crisis: Australian Gov Warns Hackers Reinfecting Systems with BadCandy Web Shell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:54:03 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #ASD #BadCandy #Cisco IOS XE #CVE_2023_20198 #cybersecurity #remote code execution #router #Web Shell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:54:03 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #ASD #BadCandy #Cisco IOS XE #CVE_2023_20198 #cybersecurity #remote code execution #router #Web Shell
Penetration Testing Tools
Cisco Router Crisis: Australian Gov Warns Hackers Reinfecting Systems with BadCandy Web Shell
Australian gov warns hackers are reinfecting Cisco IOS XE routers with the BadCandy web shell, exploiting the unpatched CVE-2023-20198 for superuser access.
⤷ Title: Beyond Human Intuition: DeepMind Launches Global AI for Math Initiative to Revolutionize Discovery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:51:03 +0000
════════════════════════
⌗ Tags: #Google #AI for Math #AlphaEvolve #Gemini Deep Think #Google DeepMind #IHES #Mathematical Discovery #science
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:51:03 +0000
════════════════════════
⌗ Tags: #Google #AI for Math #AlphaEvolve #Gemini Deep Think #Google DeepMind #IHES #Mathematical Discovery #science
Penetration Testing Tools
Beyond Human Intuition: DeepMind Launches Global AI for Math Initiative to Revolutionize Discovery
DeepMind launched the AI for Math Initiative, uniting 5 top institutes to use Gemini Deep Think and AlphaEvolve to accelerate math discovery and break records.
⤷ Title: House Spy: Robot Vacuum Halted Remotely After Engineer Blocks China Telemetry
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:45:09 +0000
════════════════════════
⌗ Tags: #Malware #Backdoor #China #iLife #IoT Security #Remote Access #Robot Vacuum #Surveillance #Telemetry
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 03 Nov 2025 03:45:09 +0000
════════════════════════
⌗ Tags: #Malware #Backdoor #China #iLife #IoT Security #Remote Access #Robot Vacuum #Surveillance #Telemetry
Penetration Testing Tools
House Spy: Robot Vacuum Halted Remotely After Engineer Blocks China Telemetry
Engineer found a secret Linux computer in his iLife robot vacuum. It uses an open ADB port to allow remote shutdown after telemetry to Chinese servers was blocked.