⤷ Title: D-Link DIR-878 Reaches EOL: 3 Unpatched RCE Flaws Allow Unauthenticated Remote Command Execution
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #D_Link #DIR_878 #EOL #rce #router security #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #D_Link #DIR_878 #EOL #rce #router security #unauthenticated access
Daily CyberSecurity
D-Link DIR-878 Reaches EOL: 3 Unpatched RCE Flaws Allow Unauthenticated Remote Command Execution
D-Link warned that DIR-878 has reached EOL with three unpatched RCE flaws. Unauthenticated remote attackers can execute arbitrary commands via Dynamic DNS and DMZ settings due to insecure CGI parameters.
⤷ Title: Critical METZ CONNECT Flaws (CVSS 9.8) Allow Unauthenticated RCE and Admin Takeover on Industrial Controllers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:43:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_41734 #EWIO_2 #ICS #METZ CONNECT #rce #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:43:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #Critical Vulnerability #CVE_2025_41734 #EWIO_2 #ICS #METZ CONNECT #rce #unauthenticated access
Daily CyberSecurity
Critical METZ CONNECT Flaws (CVSS 9.8) Allow Unauthenticated RCE and Admin Takeover on Industrial Controllers
METZ CONNECT patched five critical flaws in EWIO-2 industrial controllers. CVE-2025-41734 allows unauthenticated PHP RCE, and CVE-2025-41733 risks admin credential reset. Update to v2.2.0 immediately.
⤷ Title: 9 Million Installs: Malicious Chrome VPN Extensions Hijack User Traffic Via Remote PAC Proxy Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:23:16 +0000
════════════════════════
⌗ Tags: #Data Leak #Malware #Chrome extension #Chrome Web Store #LayerX #PAC Proxy #surveillance #Traffic Hijacking #VPN Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:23:16 +0000
════════════════════════
⌗ Tags: #Data Leak #Malware #Chrome extension #Chrome Web Store #LayerX #PAC Proxy #surveillance #Traffic Hijacking #VPN Malware
Daily CyberSecurity
9 Million Installs: Malicious Chrome VPN Extensions Hijack User Traffic Via Remote PAC Proxy Injection
LayerX exposed a 6-year, 9M-install campaign: Fake VPN/ad-blocking Chrome extensions hijack all user traffic via remote PAC proxy scripts, enabling surveillance and data exfiltration.
⤷ Title: Critical SolarWinds Serv-U Flaws (CVSS 9.1) Allow Authenticated Admin RCE and Path Bypass
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authenticated RCE #Critical Vulnerability #CVE_2025_40547 #Path Bypass #rce #SolarWinds Serv_U
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:12:06 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authenticated RCE #Critical Vulnerability #CVE_2025_40547 #Path Bypass #rce #SolarWinds Serv_U
Daily CyberSecurity
Critical SolarWinds Serv-U Flaws (CVSS 9.1) Allow Authenticated Admin RCE and Path Bypass
SolarWinds patched three Critical RCE flaws (CVSS 9.1) in Serv-U. An authenticated admin can exploit them for code execution and directory path bypass. Update to v15.5.3 immediately.
⤷ Title: npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:05:53 +0000
════════════════════════
⌗ Tags: #Malware #Adspect #anti_analysis #Cloaking #crypto phishing #fake CAPTCHA #npm #supply chain attack
Daily CyberSecurity
npm Supply Chain Attack: Hackers Use Adspect Cloaking and Fake Crypto CAPTCHA to Deceive Victims and Researchers
Socket exposed a new npm attack (dino_reborn) using Adspect cloaking to hide behind a fake crypto CAPTCHA for victims, while showing a polished decoy site (Offlido) to researchers.
⤷ Title: From Beginner to OSCP, LPT Master, CISSP & CISO in 5 Years — The Ultimate Cybersecurity Growth…
════════════════════════
𐀪 Author: Monu Jangra
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:07:49 GMT
════════════════════════
⌗ Tags: #blockchain #ai #cybersecurity #hacking #technology
════════════════════════
𐀪 Author: Monu Jangra
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:07:49 GMT
════════════════════════
⌗ Tags: #blockchain #ai #cybersecurity #hacking #technology
Medium
🚀 From Beginner to OSCP, LPT Master, CISSP & CISO in 5 Years — The Ultimate Cybersecurity Growth Blueprint
Cybersecurity is one of the rare fields where a curious beginner can transform into an elite red-teamer, certified cybersecurity leader…
⤷ Title: Crack the Gate 2 web challenge write-up
════════════════════════
𐀪 Author: -_ENIGMA_-
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:09:54 GMT
════════════════════════
⌗ Tags: #hacking #ctf #ctf_walkthrough #ctf_writeup #penetration_testing
════════════════════════
𐀪 Author: -_ENIGMA_-
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:09:54 GMT
════════════════════════
⌗ Tags: #hacking #ctf #ctf_walkthrough #ctf_writeup #penetration_testing
Medium
Crack the Gate 2 web challenge write-up
السـلام علـيكم و رحـمة اللّـه و بـركاته
⤷ Title: : (Easy)
════════════════════════
𐀪 Author: Karthikparambil
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:45 GMT
════════════════════════
⌗ Tags: #ctf #ctf_writeup #web_penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Karthikparambil
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:45 GMT
════════════════════════
⌗ Tags: #ctf #ctf_writeup #web_penetration_testing #cybersecurity
Medium
𝐌𝐢𝐬𝐬𝐢𝐨𝐧: 𝐒𝐩𝐚𝐜𝐞 𝐂𝐓𝐅 (Easy)
A Complete Walkthrough from Foothold to Root
⤷ Title: Authorization for MCP: OAuth 2.1, PRMs, and Best Practices
════════════════════════
𐀪 Author: Tahmeed Zaman
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:24:28 GMT
════════════════════════
⌗ Tags: #ai_agent #oauth #model_context_protocol #artificial_intelligence #cybersecurity
════════════════════════
𐀪 Author: Tahmeed Zaman
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:24:28 GMT
════════════════════════
⌗ Tags: #ai_agent #oauth #model_context_protocol #artificial_intelligence #cybersecurity
⤷ Title: The Massive Cloudflare Outage of November 18, 2025: What Happened, Why It Broke, and What We…
════════════════════════
𐀪 Author: Shruti yadav
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:21:44 GMT
════════════════════════
⌗ Tags: #incident_analysis #internet_outage #cybersecurity #cloudflare #network_infrastructure
════════════════════════
𐀪 Author: Shruti yadav
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:21:44 GMT
════════════════════════
⌗ Tags: #incident_analysis #internet_outage #cybersecurity #cloudflare #network_infrastructure
Medium
The Massive Cloudflare Outage of November 18, 2025: What Happened, Why It Broke, and What We…
On November 18, 2025, a large portion of the internet appeared to malfunction for a few hours. Major platforms, including X, ChatGPT…
⤷ Title: Indonesia’s Hidden Islands Show Why Connectivity is Security
════════════════════════
𐀪 Author: Isa Amanda Julia
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #education #technology
════════════════════════
𐀪 Author: Isa Amanda Julia
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:59:02 GMT
════════════════════════
⌗ Tags: #cybersecurity #education #technology
Medium
Indonesia’s Hidden Islands Show Why Connectivity is Security
Jakarta pulses with a digital heartbeat. Beneath its skyscrapers, high-speed internet flows effortlessly, fueling global commerce and…
⤷ Title: CVE-2025-63872: SVG-Based XSS in DeepSeek Chat V3.2
════════════════════════
𐀪 Author: Vinit Kundu
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:35:37 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #vulnerability_disclosure #llm_security #cve
════════════════════════
𐀪 Author: Vinit Kundu
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:35:37 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #vulnerability_disclosure #llm_security #cve
Medium
CVE-2025-63872: SVG-Based XSS in DeepSeek Chat V3.2
Discovered by Vinit Kundu
⤷ Title: The Hidden Complexity of Secure Serialization & Deserialization in Modern Distributed Systems
════════════════════════
𐀪 Author: Bervice
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:33:53 GMT
════════════════════════
⌗ Tags: #software_engineering #microservices #bervice #backend_engineering #cybersecurity
════════════════════════
𐀪 Author: Bervice
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:33:53 GMT
════════════════════════
⌗ Tags: #software_engineering #microservices #bervice #backend_engineering #cybersecurity
Medium
The Hidden Complexity of Secure Serialization & Deserialization in Modern Distributed Systems
Serialization looks simple on the surface — convert an object into a byte stream, transmit it, and reconstruct it on the other side. But…
⤷ Title: BANKING RENOVATION FOR 2030
════════════════════════
𐀪 Author: Shantanukumarsahoo Sbi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:15:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #sustainable_banking #financial_inclusion #digitla_transformation
════════════════════════
𐀪 Author: Shantanukumarsahoo Sbi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:15:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #artificial_intelligence #sustainable_banking #financial_inclusion #digitla_transformation
Medium
BANKING RENOVATION FOR 2030
A Deep Strategic Blueprint for the Future of Banking
⤷ Title: professional-proxy-solutions
════════════════════════
𐀪 Author: WeiWizard
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:11:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_engineering #proxy #ecommerce_tool #network_infrastructure
════════════════════════
𐀪 Author: WeiWizard
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 02:11:18 GMT
════════════════════════
⌗ Tags: #cybersecurity #data_engineering #proxy #ecommerce_tool #network_infrastructure
Medium
professional-proxy-solutions
How Professional Proxy Solutions Support Scalable US Operations
⤷ Title: OWASP Top 10 2025: Insecure Data Handling
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:26 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #cryptographicfailure #tryhackme_walkthrough #owasp_top_10 #tryhackme
════════════════════════
𐀪 Author: THM{0x416469747961204D6163686972616A75}
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:46:26 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #cryptographicfailure #tryhackme_walkthrough #owasp_top_10 #tryhackme
Medium
OWASP Top 10 2025: Insecure Data Handling
Learn about A04, A05, and A08 as they related to insecure data handling.
⤷ Title: I Finally Understood XSS and SQL Injection After Seeing This Demo
════════════════════════
𐀪 Author: CodeByUmar
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:38:32 GMT
════════════════════════
⌗ Tags: #coding #sql_injection #xss_attack #web_development #software_development
════════════════════════
𐀪 Author: CodeByUmar
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 03:38:32 GMT
════════════════════════
⌗ Tags: #coding #sql_injection #xss_attack #web_development #software_development
Medium
I Finally Understood XSS and SQL Injection After Seeing This Demo
A hands-on demo that makes the mechanics of XSS and SQL injection impossible to forget and shows the exact fixes you should apply today.
⤷ Title: Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 09:50:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 09:50:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: xurlfind3r: The Cross-Platform Tool for Passive and Efficient URL Discovery
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 04:18:57 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLItool #cybersecurity #OSINT #PassiveReconnaissance #SecurityResearch #URLDiscovery #xurlfind3r
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 04:18:57 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLItool #cybersecurity #OSINT #PassiveReconnaissance #SecurityResearch #URLDiscovery #xurlfind3r
Penetration Testing Tools
xurlfind3r: The Cross-Platform Tool for Passive and Efficient URL Discovery
xurlfind3r is a cross-platform command-line tool designed for efficient, passive URL discovery by gathering domain information from multiple online public sources.
⤷ Title: Exploit Released for Critical Monsta FTP RCE Vulnerability (CVE-2025-34299)
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 04:11:26 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CVE_2025_34299 #MonstaFTP #PythonExploit #RCE #ReverseShell #vulnerability #WebSecurity
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 04:11:26 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CVE_2025_34299 #MonstaFTP #PythonExploit #RCE #ReverseShell #vulnerability #WebSecurity
Penetration Testing Tools
Exploit Released for Critical Monsta FTP RCE Vulnerability (CVE-2025-34299)
A Python exploit has been released for a critical Monsta FTP RCE flaw (CVE-2025-34299). The bug allows arbitrary PHP code execution by exploiting the downloadFile function.