⤷ Title: GitLab CVE-2023–7028 | TryHackMe
════════════════════════
𐀪 Author: q1mthi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:34:26 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #vulnerability #exploitation #tryhackme #penetration_testing
════════════════════════
𐀪 Author: q1mthi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:34:26 GMT
════════════════════════
⌗ Tags: #tryhackme_walkthrough #vulnerability #exploitation #tryhackme #penetration_testing
Medium
GitLab CVE-2023–7028 | TryHackMe
A vulnerability that allows unauthorized users to take over user accounts, potentially including administrator accounts, without any…
⤷ Title: EchoEcho CTF Writeup — by vulnbydefault
════════════════════════
𐀪 Author: Bader ALmutairi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:05:48 GMT
════════════════════════
⌗ Tags: #ctf #rce #bypass #vulnbydefault #ctf_writeup
════════════════════════
𐀪 Author: Bader ALmutairi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 01:05:48 GMT
════════════════════════
⌗ Tags: #ctf #rce #bypass #vulnbydefault #ctf_writeup
Medium
💻 EchoEcho CTF Writeup — by vulnbydefault
السلام عليكم ورحمة الله
⤷ Title: CISA KEV Alert: FortiWeb RCE Flaw (CVE-2025-58034) Under Active Exploitation for Command Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:26:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58034 #FortiWeb #os command injection #rce #waf #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:26:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Active Exploitation #CISA KEV #CVE_2025_58034 #FortiWeb #os command injection #rce #waf #zero_day
Daily CyberSecurity
CISA KEV Alert: FortiWeb RCE Flaw (CVE-2025-58034) Under Active Exploitation for Command Injection
CISA added a FortiWeb RCE flaw (CVE-2025-58034) to its KEV Catalog due to active exploitation. The bug allows authenticated attackers to execute arbitrary code on the WAF via crafted requests. Update now.
⤷ Title: AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:08:39 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #AI_generated malware #botnet #cryptomining #CVE_2023_48022 #Oligo Security #Ray AI #ShadowRay 2.0
Daily CyberSecurity
AI-Generated Malware Attacks 230,000 Exposed Ray AI Clusters in Massive ShadowRay 2.0 Botnet Campaign
Oligo exposed ShadowRay 2.0, a massive, evolving campaign using AI-generated malware to turn 230K exposed Ray AI clusters into a self-propagating cryptomining and DDoS botnet.
⤷ Title: D-Link DIR-878 Reaches EOL: 3 Unpatched RCE Flaws Allow Unauthenticated Remote Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #D_Link #DIR_878 #EOL #rce #router security #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #D_Link #DIR_878 #EOL #rce #router security #unauthenticated access
Daily CyberSecurity
D-Link DIR-878 Reaches EOL: 3 Unpatched RCE Flaws Allow Unauthenticated Remote Command Execution
D-Link warned that DIR-878 has reached EOL with three unpatched RCE flaws. Unauthenticated remote attackers can execute arbitrary commands via Dynamic DNS and DMZ settings due to insecure CGI parameters.
⤷ Title: Critical METZ CONNECT Flaws (CVSS 9.8) Allow Unauthenticated RCE and Admin Takeover on Industrial Controllers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:43:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_41734 #EWIO_2 #ICS #METZ CONNECT #rce #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:43:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_41734 #EWIO_2 #ICS #METZ CONNECT #rce #unauthenticated access
Daily CyberSecurity
Critical METZ CONNECT Flaws (CVSS 9.8) Allow Unauthenticated RCE and Admin Takeover on Industrial Controllers
METZ CONNECT patched five critical flaws in EWIO-2 industrial controllers. CVE-2025-41734 allows unauthenticated PHP RCE, and CVE-2025-41733 risks admin credential reset. Update to v2.2.0 immediately.
⤷ Title: 9 Million Installs: Malicious Chrome VPN Extensions Hijack User Traffic Via Remote PAC Proxy Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:23:16 +0000
════════════════════════
⌗ Tags: #Data Leak #Malware #Chrome extension #Chrome Web Store #LayerX #PAC Proxy #surveillance #Traffic Hijacking #VPN Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:23:16 +0000
════════════════════════
⌗ Tags: #Data Leak #Malware #Chrome extension #Chrome Web Store #LayerX #PAC Proxy #surveillance #Traffic Hijacking #VPN Malware
Daily CyberSecurity
9 Million Installs: Malicious Chrome VPN Extensions Hijack User Traffic Via Remote PAC Proxy Injection
LayerX exposed a 6-year, 9M-install campaign: Fake VPN/ad-blocking Chrome extensions hijack all user traffic via remote PAC proxy scripts, enabling surveillance and data exfiltration.
⤷ Title: Critical SolarWinds Serv-U Flaws (CVSS 9.1) Allow Authenticated Admin RCE and Path Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authenticated RCE #Critical Vulnerability #CVE_2025_40547 #Path Bypass #rce #SolarWinds Serv_U
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authenticated RCE #Critical Vulnerability #CVE_2025_40547 #Path Bypass #rce #SolarWinds Serv_U
Daily CyberSecurity
Critical SolarWinds Serv-U Flaws (CVSS 9.1) Allow Authenticated Admin RCE and Path Bypass
SolarWinds patched three Critical RCE flaws (CVSS 9.1) in Serv-U. An authenticated admin can exploit them for code execution and directory path bypass. Update to v15.5.3 immediately.
⤷ Title: npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
Daily CyberSecurity
npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
Socket exposed a new npm attack (dino_reborn) using Adspect cloaking to hide behind a fake crypto CAPTCHA for victims, while showing a polished decoy site (Offlido) to researchers.
⤷ Title: From Beginner to OSCP, LPT Master, CISSP & CISO in 5 Years — The Ultimate Cybersecurity Growth…
════════════════════════
𐀪 Author: Monu Jangra
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:07:49 GMT
════════════════════════
⌗ Tags: #blockchain #ai #cybersecurity #hacking #technology
════════════════════════
𐀪 Author: Monu Jangra
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:07:49 GMT
════════════════════════
⌗ Tags: #blockchain #ai #cybersecurity #hacking #technology
Medium
🚀 From Beginner to OSCP, LPT Master, CISSP & CISO in 5 Years — The Ultimate Cybersecurity Growth Blueprint
Cybersecurity is one of the rare fields where a curious beginner can transform into an elite red-teamer, certified cybersecurity leader…
⤷ Title: Crack the Gate 2 web challenge write-up
════════════════════════
𐀪 Author: -_ENIGMA_-
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:09:54 GMT
════════════════════════
⌗ Tags: #hacking #ctf #ctf_walkthrough #ctf_writeup #penetration_testing
════════════════════════
𐀪 Author: -_ENIGMA_-
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:09:54 GMT
════════════════════════
⌗ Tags: #hacking #ctf #ctf_walkthrough #ctf_writeup #penetration_testing
Medium
Crack the Gate 2 web challenge write-up
السـلام علـيكم و رحـمة اللّـه و بـركاته
⤷ Title: : (Easy)
════════════════════════
𐀪 Author: Karthikparambil
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:45 GMT
════════════════════════
⌗ Tags: #ctf #ctf_writeup #web_penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Karthikparambil
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:45 GMT
════════════════════════
⌗ Tags: #ctf #ctf_writeup #web_penetration_testing #cybersecurity
Medium
𝐌𝐢𝐬𝐬𝐢𝐨𝐧: 𝐒𝐩𝐚𝐜𝐞 𝐂𝐓𝐅 (Easy)
A Complete Walkthrough from Foothold to Root
⤷ Title: Authorization for MCP: OAuth 2.1, PRMs, and Best Practices
════════════════════════
𐀪 Author: Tahmeed Zaman
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:24:28 GMT
════════════════════════
⌗ Tags: #ai_agent #oauth #model_context_protocol #artificial_intelligence #cybersecurity
════════════════════════
𐀪 Author: Tahmeed Zaman
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:24:28 GMT
════════════════════════
⌗ Tags: #ai_agent #oauth #model_context_protocol #artificial_intelligence #cybersecurity
⤷ Title: The Massive Cloudflare Outage of November 18, 2025: What Happened, Why It Broke, and What We…
════════════════════════
𐀪 Author: Shruti yadav
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:21:44 GMT
════════════════════════
⌗ Tags: #incident_analysis #internet_outage #cybersecurity #cloudflare #network_infrastructure
════════════════════════
𐀪 Author: Shruti yadav
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:21:44 GMT
════════════════════════
⌗ Tags: #incident_analysis #internet_outage #cybersecurity #cloudflare #network_infrastructure
Medium
The Massive Cloudflare Outage of November 18, 2025: What Happened, Why It Broke, and What We…
On November 18, 2025, a large portion of the internet appeared to malfunction for a few hours. Major platforms, including X, ChatGPT…
⤷ Title: Indonesia’s Hidden Islands Show Why Connectivity is Security
════════════════════════
𐀪 Author: Isa Amanda Julia
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #education #technology
════════════════════════
𐀪 Author: Isa Amanda Julia
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #education #technology
Medium
Indonesia’s Hidden Islands Show Why Connectivity is Security
Jakarta pulses with a digital heartbeat. Beneath its skyscrapers, high-speed internet flows effortlessly, fueling global commerce and…
⤷ Title: CVE-2025-63872: SVG-Based XSS in DeepSeek Chat V3.2
════════════════════════
𐀪 Author: Vinit Kundu
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:35:37 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #vulnerability_disclosure #llm_security #cve
════════════════════════
𐀪 Author: Vinit Kundu
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:35:37 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #vulnerability_disclosure #llm_security #cve
Medium
CVE-2025-63872: SVG-Based XSS in DeepSeek Chat V3.2
Discovered by Vinit Kundu
⤷ Title: The Hidden Complexity of Secure Serialization & Deserialization in Modern Distributed Systems
════════════════════════
𐀪 Author: Bervice
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:33:53 GMT
════════════════════════
⌗ Tags: #software_engineering #microservices #bervice #backend_engineering #cybersecurity
════════════════════════
𐀪 Author: Bervice
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:33:53 GMT
════════════════════════
⌗ Tags: #software_engineering #microservices #bervice #backend_engineering #cybersecurity
Medium
The Hidden Complexity of Secure Serialization & Deserialization in Modern Distributed Systems
Serialization looks simple on the surface — convert an object into a byte stream, transmit it, and reconstruct it on the other side. But…
⤷ Title: BANKING RENOVATION FOR 2030
════════════════════════
𐀪 Author: Shantanukumarsahoo Sbi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:15:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #sustainable_banking #financial_inclusion #digitla_transformation
════════════════════════
𐀪 Author: Shantanukumarsahoo Sbi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:15:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #sustainable_banking #financial_inclusion #digitla_transformation
Medium
BANKING RENOVATION FOR 2030
A Deep Strategic Blueprint for the Future of Banking
⤷ Title: professional-proxy-solutions
════════════════════════
𐀪 Author: WeiWizard
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:11:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_engineering #proxy #ecommerce_tool #network_infrastructure
════════════════════════
𐀪 Author: WeiWizard
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:11:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_engineering #proxy #ecommerce_tool #network_infrastructure
Medium
professional-proxy-solutions
How Professional Proxy Solutions Support Scalable US Operations
⤷ Title: OWASP Top 10 2025: Insecure Data Handling
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:26 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #cryptographicfailure #tryhackme_walkthrough #owasp_top_10 #tryhackme
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:26 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #cryptographicfailure #tryhackme_walkthrough #owasp_top_10 #tryhackme
Medium
OWASP Top 10 2025: Insecure Data Handling
Learn about A04, A05, and A08 as they related to insecure data handling.