⤷ Title: Cross Site Scripting (XSS)
════════════════════════
𐀪 Author: Enes Demir
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:40:04 GMT
════════════════════════
⌗ Tags: #xss_bypass #xss_attack #xss_vulnerability #cybersecurity
════════════════════════
𐀪 Author: Enes Demir
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:40:04 GMT
════════════════════════
⌗ Tags: #xss_bypass #xss_attack #xss_vulnerability #cybersecurity
Medium
Cross Site Scripting (XSS)
XSS saldırıları, bir web uygulamasının kullanıcı girdilerini yeterince doğrulamadığı ve filtrelemediği durumlarda ortaya çıkar.
⤷ Title: CSRF — Cross-site Request Forgery nedir ?
════════════════════════
𐀪 Author: Enes Demir
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:37:53 GMT
════════════════════════
⌗ Tags: #csrf #cybersecurity
════════════════════════
𐀪 Author: Enes Demir
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:37:53 GMT
════════════════════════
⌗ Tags: #csrf #cybersecurity
Medium
CSRF — Cross-site Request Forgery nedir ?
CSRF (Cross-Site Request Forgery)
⤷ Title: IDOR — Insecure Direct Object Referance Nedir
════════════════════════
𐀪 Author: Enes Demir
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:36:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #idor
════════════════════════
𐀪 Author: Enes Demir
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:36:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #idor
Medium
IDOR — Insecure Direct Object Referance Nedir
Insecure direct object references (IDOR) bir erişim kontrolü zâfiyetidir. bir uygulamanın nesnelere doğrudan erişmek için kullanıcı…
⤷ Title: Welcome — What I’ll Be Writing About on Medium
════════════════════════
𐀪 Author: Hamza Gharandoq
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:19:33 GMT
════════════════════════
⌗ Tags: #digital_ethic #information_security #grc #technologylaw #cybersecurity
════════════════════════
𐀪 Author: Hamza Gharandoq
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:19:33 GMT
════════════════════════
⌗ Tags: #digital_ethic #information_security #grc #technologylaw #cybersecurity
Medium
Welcome — What I’ll Be Writing About on Medium
Sharing cybersecurity, GRC, tech law, and practical InfoSec insights — written simply and clearly.
❤1
⤷ Title: ICA-1 — Full Walk-through & Mastery: Decoding Base64, Custom Recon Tool
════════════════════════
𐀪 Author: Shikhar Sinha
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 20:42:51 GMT
════════════════════════
⌗ Tags: #vulnhub_walkthrough #ethical_hacking #vulnhub #ctf_walkthrough #penetration_testing
════════════════════════
𐀪 Author: Shikhar Sinha
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 20:42:51 GMT
════════════════════════
⌗ Tags: #vulnhub_walkthrough #ethical_hacking #vulnhub #ctf_walkthrough #penetration_testing
Medium
ICA-1 — Full Walk-through & Mastery: Decoding Base64, Custom Recon Tool
Hello! I’m an aspiring pentester and cybersecurity researcher, and I regularly practice on VulnHub machines to sharpen my skills. While…
⤷ Title: Cybersecurity Career Roadmap 2025: Step-by-Step Guide from Beginner to Professional |kidnapshadow
════════════════════════
𐀪 Author: Kidnapshadow
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 20:05:27 GMT
════════════════════════
⌗ Tags: #tech_career #career_development #cybersecurity_careers #cybersecurity #ethical_hacking
════════════════════════
𐀪 Author: Kidnapshadow
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 20:05:27 GMT
════════════════════════
⌗ Tags: #tech_career #career_development #cybersecurity_careers #cybersecurity #ethical_hacking
Medium
Cybersecurity Career Roadmap 2025: Step-by-Step Guide from Beginner to Professional | kidnapshadow ✨
Cybersecurity today is more than a career path — it’s a real-world mission. Every organization, big or small, is dealing with constant…
⤷ Title: Mobile Hacking Lab “Post Board” Writeup
════════════════════════
𐀪 Author: Akshay Ravi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 20:43:44 GMT
════════════════════════
⌗ Tags: #rce #mobileapplicationsecurity #android_pentesting #deeplink #reverse_engineering
════════════════════════
𐀪 Author: Akshay Ravi
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 20:43:44 GMT
════════════════════════
⌗ Tags: #rce #mobileapplicationsecurity #android_pentesting #deeplink #reverse_engineering
Medium
Mobile Hacking Lab “Post Board” Writeup
This article is a write up on the Mobile Hacking Lab “Post Board” challenge, where the main objective is to exploit a Cross Site Scripting…
⤷ Title: Intigriti Challenge 1125: From JWT Bypass to RCE
════════════════════════
𐀪 Author: msfire
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:44:00 GMT
════════════════════════
⌗ Tags: #intigriti #ctf #ctf_writeup #bug_bounty_writeup #ctf_walkthrough
════════════════════════
𐀪 Author: msfire
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 21:44:00 GMT
════════════════════════
⌗ Tags: #intigriti #ctf #ctf_writeup #bug_bounty_writeup #ctf_walkthrough
Medium
Intigriti Challenge 1125: From JWT Bypass to RCE
This write-up details the solution for the Intigriti Challenge 1125. Unlike standard technical reports, this post focuses on the…
⤷ Title: PICing AOP
════════════════════════
𐀪 Author: Rasta Mouse
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 23:02:32 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Rasta Mouse
════════════════════════
ⴵ Time: Wed, 19 Nov 2025 23:02:32 GMT
════════════════════════
⌗ Tags: No_Tags
Rasta Mouse
PICing AOP
The 11.10.25 Crystal Palace release added more new commands in one go than I think I've seen thus far. Many of them seemed really similar at first blush, and it took me a while to get an understanding of where each one is applicable (I failed in that
⤷ Title: Critical ASUSTOR Flaw (CVE-2025-13051) Allows Local DLL Hijacking for SYSTEM Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 01:09:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 01:09:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
Daily CyberSecurity
Critical ASUSTOR Flaw (CVE-2025-13051) Allows Local DLL Hijacking for SYSTEM Privilege Escalation
A Critical DLL Hijacking flaw (CVE-2025-13051) in ASUSTOR Backup Plan/EZSync allows local attackers to gain SYSTEM privileges by planting a malicious DLL in a user-writable path. Update immediately.
⤷ Title: Critical CVE-2025-65015 Vulnerability in joserfc Could Let Attackers Exhaust Server Resources via Oversized JWT Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:45:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65015 #Denial of Service #dos #joserfc #JWT #Python #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:45:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65015 #Denial of Service #dos #joserfc #JWT #Python #Supply Chain
Daily CyberSecurity
Critical CVE-2025-65015 Vulnerability in joserfc Could Let Attackers Exhaust Server Resources via Oversized JWT Tokens
A Critical DoS flaw (CVE-2025-65015) in joserfc allows unauthenticated attackers to overwhelm log/SIEM systems by injecting massive JWT payloads into exception messages.
⤷ Title: CISA/FBI/NSA Unite to Dismantle Bulletproof Hosting Ecosystem with New Global Defense Guide
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:43:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BPH #bulletproof hosting #CISA #Cybersecurity Guide #Global Takedown #ISP Security #phishing #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:43:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BPH #bulletproof hosting #CISA #Cybersecurity Guide #Global Takedown #ISP Security #phishing #ransomware
Daily CyberSecurity
CISA/FBI/NSA Unite to Dismantle Bulletproof Hosting Ecosystem with New Global Defense Guide
CISA, NSA, and FBI released a guide to dismantle Bulletproof Hosting (BPH) networks. It advises ISPs on precision filtering and stricter vetting to curb infrastructure used by ransomware and phishing campaigns.
⤷ Title: Lazarus Group’s New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
Daily CyberSecurity
Lazarus Group's New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
A deep-dive on Lazarus’s ScoringMathTea RAT reveals a full reflective DLL injection system, TEA/XTEA C2 encryption, and a polyalphabetic cipher for API hashing—a highly evasive tool for espionage.
⤷ Title: One Click, 42 Days: Akira Ransomware Used CAPTCHA Decoy to Destroy Cloud Backups and Cripple Storage Firm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:27:43 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #ClickFix #Cloud Backup Destruction #EDR Visibility #Howling Scorpius #lateral movement #SecTopRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:27:43 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #ClickFix #Cloud Backup Destruction #EDR Visibility #Howling Scorpius #lateral movement #SecTopRAT
Daily CyberSecurity
One Click, 42 Days: Akira Ransomware Used CAPTCHA Decoy to Destroy Cloud Backups and Cripple Storage Firm
A 42-day Akira ransomware attack started with one ClickFix CAPTCHA that deployed SectopRAT. The attackers went undetected despite EDRs, stealing 1 TB and deleting cloud storage backups.
⤷ Title: Sophisticated “The Gentlemen” Ransomware RaaS Emerges with XChaCha20 Encryption and 48 Victims in 3 Months
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Malware #Curve25519 #Cybereason #Double Extortion #lateral movement #RaaS #ransomware #The Gentlemen #XChaCha20
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Malware #Curve25519 #Cybereason #Double Extortion #lateral movement #RaaS #ransomware #The Gentlemen #XChaCha20
Daily CyberSecurity
Sophisticated "The Gentlemen" Ransomware RaaS Emerges with XChaCha20 Encryption and 48 Victims in 3 Months
Cybereason exposed The Gentlemen, a new, technically advanced Go-based RaaS using XChaCha20/Curve25519 crypto. The group claimed 48 victims in 3 months, leveraging WMI and PowerShell for propagation.
⤷ Title: Next-Gen Stealth: Malware Hides C2 Traffic as Fake LLM API Requests on Tencent Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:20:18 +0000
════════════════════════
⌗ Tags: #Malware #C2 Evasion #DLL Sideloading #Fake LLM API #LLM Traffic #rat #Remote Access Trojan #Tencent Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:20:18 +0000
════════════════════════
⌗ Tags: #Malware #C2 Evasion #DLL Sideloading #Fake LLM API #LLM Traffic #rat #Remote Access Trojan #Tencent Cloud
⤷ Title: Next-Gen Ransomware Targets AWS S3: Five Cloud-Native Variants Exploit Misconfigurations for Irreversible Data Destruction
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Malware #AWS S3 #Cloud Security #cloud_native #Extortion #IAM #KMS #ransomware #SSE_C #Trend Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Malware #AWS S3 #Cloud Security #cloud_native #Extortion #IAM #KMS #ransomware #SSE_C #Trend Research
Daily CyberSecurity
Next-Gen Ransomware Targets AWS S3: Five Cloud-Native Variants Exploit Misconfigurations for Irreversible Data Destruction
Trend Research warns that ransomware is shifting to AWS S3, exploiting misconfigured IAM and SSE-C keys in five attack variants to cause irreversible data loss and cloud-native extortion.
⤷ Title: Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and Access Resale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
Daily CyberSecurity
Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and…
Broadcom exposed a group deploying multiple RMM tools (ScreenConnect, LogMeIn, Naverisk) weeks apart to achieve redundant persistence. The likely Initial Access Broker (IAB) prepares systems for resale.
⤷ Title: Critical Apache Causeway RCE Flaw (CVE-2025-64408) Allows Authenticated Code Execution via Java Deserialization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:05:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Causeway #Critical Vulnerability #CVE_2025_64408 #Java deserialization #rce #ViewModel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:05:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Causeway #Critical Vulnerability #CVE_2025_64408 #Java deserialization #rce #ViewModel
Daily CyberSecurity
Critical Apache Causeway RCE Flaw (CVE-2025-64408) Allows Authenticated Code Execution via Java Deserialization
Apache patched a Critical RCE flaw (CVE-2025-64408) in Causeway allowing authenticated attackers to execute arbitrary code via Java deserialization in the ViewModel component. Update to v3.5.0.
⤷ Title: No More Public BSODs: Windows 11 Will Hide Crash Screens on Public Displays
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:03:45 +0000
════════════════════════
⌗ Tags: #Windows #BSOD #CosmeticFix #DigitalSignage #Microsoft #PublicDisplay #SystemCrash #Windows11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:03:45 +0000
════════════════════════
⌗ Tags: #Windows #BSOD #CosmeticFix #DigitalSignage #Microsoft #PublicDisplay #SystemCrash #Windows11
Daily CyberSecurity
No More Public BSODs: Windows 11 Will Hide Crash Screens on Public Displays
Microsoft will introduce a feature for public display systems (digital signage) to hide crash screens (BSOD) after 15 seconds, making the system appear off rather than crashed.