⤷ Title: Critical ASUSTOR Flaw (CVE-2025-13051) Allows Local DLL Hijacking for SYSTEM Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 01:09:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 01:09:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report
Daily CyberSecurity
Critical ASUSTOR Flaw (CVE-2025-13051) Allows Local DLL Hijacking for SYSTEM Privilege Escalation
A Critical DLL Hijacking flaw (CVE-2025-13051) in ASUSTOR Backup Plan/EZSync allows local attackers to gain SYSTEM privileges by planting a malicious DLL in a user-writable path. Update immediately.
⤷ Title: Critical CVE-2025-65015 Vulnerability in joserfc Could Let Attackers Exhaust Server Resources via Oversized JWT Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:45:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65015 #Denial of Service #dos #joserfc #JWT #Python #Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:45:54 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #CVE_2025_65015 #Denial of Service #dos #joserfc #JWT #Python #Supply Chain
Daily CyberSecurity
Critical CVE-2025-65015 Vulnerability in joserfc Could Let Attackers Exhaust Server Resources via Oversized JWT Tokens
A Critical DoS flaw (CVE-2025-65015) in joserfc allows unauthenticated attackers to overwhelm log/SIEM systems by injecting massive JWT payloads into exception messages.
⤷ Title: CISA/FBI/NSA Unite to Dismantle Bulletproof Hosting Ecosystem with New Global Defense Guide
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:43:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BPH #bulletproof hosting #CISA #Cybersecurity Guide #Global Takedown #ISP Security #phishing #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:43:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BPH #bulletproof hosting #CISA #Cybersecurity Guide #Global Takedown #ISP Security #phishing #ransomware
Daily CyberSecurity
CISA/FBI/NSA Unite to Dismantle Bulletproof Hosting Ecosystem with New Global Defense Guide
CISA, NSA, and FBI released a guide to dismantle Bulletproof Hosting (BPH) networks. It advises ISPs on precision filtering and stricter vetting to curb infrastructure used by ransomware and phishing campaigns.
⤷ Title: Lazarus Group’s New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:39:19 +0000
════════════════════════
⌗ Tags: #Malware #API hashing #cyber_espionage #Lazarus Group #Polyalphabetic Cipher #rat #Reflective DLL Injection #ScoringMathTea #TEA/XTEA
Daily CyberSecurity
Lazarus Group's New ScoringMathTea RAT Uses Reflective Plugin Loader and Custom Polyalphabetic Crypto for Espionage
A deep-dive on Lazarus’s ScoringMathTea RAT reveals a full reflective DLL injection system, TEA/XTEA C2 encryption, and a polyalphabetic cipher for API hashing—a highly evasive tool for espionage.
⤷ Title: One Click, 42 Days: Akira Ransomware Used CAPTCHA Decoy to Destroy Cloud Backups and Cripple Storage Firm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:27:43 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #ClickFix #Cloud Backup Destruction #EDR Visibility #Howling Scorpius #lateral movement #SecTopRAT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:27:43 +0000
════════════════════════
⌗ Tags: #Malware #Akira ransomware #ClickFix #Cloud Backup Destruction #EDR Visibility #Howling Scorpius #lateral movement #SecTopRAT
Daily CyberSecurity
One Click, 42 Days: Akira Ransomware Used CAPTCHA Decoy to Destroy Cloud Backups and Cripple Storage Firm
A 42-day Akira ransomware attack started with one ClickFix CAPTCHA that deployed SectopRAT. The attackers went undetected despite EDRs, stealing 1 TB and deleting cloud storage backups.
⤷ Title: Sophisticated “The Gentlemen” Ransomware RaaS Emerges with XChaCha20 Encryption and 48 Victims in 3 Months
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Malware #Curve25519 #Cybereason #Double Extortion #lateral movement #RaaS #ransomware #The Gentlemen #XChaCha20
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:25:44 +0000
════════════════════════
⌗ Tags: #Malware #Curve25519 #Cybereason #Double Extortion #lateral movement #RaaS #ransomware #The Gentlemen #XChaCha20
Daily CyberSecurity
Sophisticated "The Gentlemen" Ransomware RaaS Emerges with XChaCha20 Encryption and 48 Victims in 3 Months
Cybereason exposed The Gentlemen, a new, technically advanced Go-based RaaS using XChaCha20/Curve25519 crypto. The group claimed 48 victims in 3 months, leveraging WMI and PowerShell for propagation.
⤷ Title: Next-Gen Stealth: Malware Hides C2 Traffic as Fake LLM API Requests on Tencent Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:20:18 +0000
════════════════════════
⌗ Tags: #Malware #C2 Evasion #DLL Sideloading #Fake LLM API #LLM Traffic #rat #Remote Access Trojan #Tencent Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:20:18 +0000
════════════════════════
⌗ Tags: #Malware #C2 Evasion #DLL Sideloading #Fake LLM API #LLM Traffic #rat #Remote Access Trojan #Tencent Cloud
⤷ Title: Next-Gen Ransomware Targets AWS S3: Five Cloud-Native Variants Exploit Misconfigurations for Irreversible Data Destruction
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Malware #AWS S3 #Cloud Security #cloud_native #Extortion #IAM #KMS #ransomware #SSE_C #Trend Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:15:07 +0000
════════════════════════
⌗ Tags: #Malware #AWS S3 #Cloud Security #cloud_native #Extortion #IAM #KMS #ransomware #SSE_C #Trend Research
Daily CyberSecurity
Next-Gen Ransomware Targets AWS S3: Five Cloud-Native Variants Exploit Misconfigurations for Irreversible Data Destruction
Trend Research warns that ransomware is shifting to AWS S3, exploiting misconfigured IAM and SSE-C keys in five attack variants to cause irreversible data loss and cloud-native extortion.
⤷ Title: Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and Access Resale
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:10:58 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Broadcom Threat Hunter #initial access broker #LogMeIn Resolve #Multi_RMM #persistence #RMM Abuse #ScreenConnect
Daily CyberSecurity
Cybercriminals Shift Tactics: Group Deploys Multiple RMM Tools (ScreenConnect, LogMeIn, Naverisk) for Redundant Persistence and…
Broadcom exposed a group deploying multiple RMM tools (ScreenConnect, LogMeIn, Naverisk) weeks apart to achieve redundant persistence. The likely Initial Access Broker (IAB) prepares systems for resale.
⤷ Title: Critical Apache Causeway RCE Flaw (CVE-2025-64408) Allows Authenticated Code Execution via Java Deserialization
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:05:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Causeway #Critical Vulnerability #CVE_2025_64408 #Java deserialization #rce #ViewModel
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:05:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Causeway #Critical Vulnerability #CVE_2025_64408 #Java deserialization #rce #ViewModel
Daily CyberSecurity
Critical Apache Causeway RCE Flaw (CVE-2025-64408) Allows Authenticated Code Execution via Java Deserialization
Apache patched a Critical RCE flaw (CVE-2025-64408) in Causeway allowing authenticated attackers to execute arbitrary code via Java deserialization in the ViewModel component. Update to v3.5.0.
⤷ Title: No More Public BSODs: Windows 11 Will Hide Crash Screens on Public Displays
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:03:45 +0000
════════════════════════
⌗ Tags: #Windows #BSOD #CosmeticFix #DigitalSignage #Microsoft #PublicDisplay #SystemCrash #Windows11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:03:45 +0000
════════════════════════
⌗ Tags: #Windows #BSOD #CosmeticFix #DigitalSignage #Microsoft #PublicDisplay #SystemCrash #Windows11
Daily CyberSecurity
No More Public BSODs: Windows 11 Will Hide Crash Screens on Public Displays
Microsoft will introduce a feature for public display systems (digital signage) to hide crash screens (BSOD) after 15 seconds, making the system appear off rather than crashed.
⤷ Title: Post-CrowdStrike: Microsoft to Phase Out OEM Kernel-Level Driver Privileges
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:00:34 +0000
════════════════════════
⌗ Tags: #Windows #CrowdStrike #DriverStandard #KernelMode #Microsoft #OEMDrivers #security #SystemStability #Windows11
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 00:00:34 +0000
════════════════════════
⌗ Tags: #Windows #CrowdStrike #DriverStandard #KernelMode #Microsoft #OEMDrivers #security #SystemStability #Windows11
Daily CyberSecurity
Post-CrowdStrike: Microsoft to Phase Out OEM Kernel-Level Driver Privileges
For years, driver-related failures have appeared with relentless regularity. Whether produced by hardware manufacturers or software vendors, faulty drivers have long been capable of destabilizing …
⤷ Title: TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:36:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:36:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 13:05:00 +0530
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Unknown
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 13:05:00 +0530
════════════════════════
⌗ Tags: No_Tags
⤷ Title: NVIDIA Crushes AI Bubble Fears with Record $57B Revenue
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:17:46 +0000
════════════════════════
⌗ Tags: #Technology #Accelerated Computing #AI Bubble #Data Center #Earnings Report #Financials #Generative AI #GPU #Jensen Huang #NVDA #nvidia
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:17:46 +0000
════════════════════════
⌗ Tags: #Technology #Accelerated Computing #AI Bubble #Data Center #Earnings Report #Financials #Generative AI #GPU #Jensen Huang #NVDA #nvidia
Daily CyberSecurity
NVIDIA Crushes AI Bubble Fears with Record $57B Revenue
NVIDIA's Q3 revenue hit a record $57B, up 62% YoY, as CEO Jensen Huang declares the AI boom is not a bubble but its "true ascent." Shares surge 5%.
⤷ Title: OpenAI Launches FREE, FERPA-Compliant ChatGPT for K–12 Teachers Until 2027
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:13:31 +0000
════════════════════════
⌗ Tags: #Technology #AI Tools #ChatGPT #Education #FERPA #free access #K_12 #Lesson Planning #OpenAI #School Tech #Teachers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 09:13:31 +0000
════════════════════════
⌗ Tags: #Technology #AI Tools #ChatGPT #Education #FERPA #free access #K_12 #Lesson Planning #OpenAI #School Tech #Teachers
Daily CyberSecurity
OpenAI Launches FREE, FERPA-Compliant ChatGPT for K–12 Teachers Until 2027
OpenAI launches ChatGPT for Teachers: FREE until 2027 for US K-12 educators. It features enhanced security, FERPA compliance, and full access to AI tools.
⤷ Title: $31.2 Billion Raised: Google Accelerator Reveals Massive Global Impact Report
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:58:46 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cloud Solutions #entrepreneurship #Global Impact #Google Accelerator #innovation #job creation #Startup Funding #Tech Startups
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:58:46 +0000
════════════════════════
⌗ Tags: #Technology #AI #Cloud Solutions #entrepreneurship #Global Impact #Google Accelerator #innovation #job creation #Startup Funding #Tech Startups
Daily CyberSecurity
$31.2 Billion Raised: Google Accelerator Reveals Massive Global Impact Report
Google's Accelerator Impact Report reveals over 1,700 alumni have raised a massive $31.2 billion and created over 109,000 jobs globally since 2016.
⤷ Title: Thunderbird 145: Native Microsoft Exchange Support Makes Outlook Migration Easy!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:50:30 +0000
════════════════════════
⌗ Tags: #Technology #email client #EWS #Exchange #Microsoft 365 #mozilla #open_source #Outlook #Productivity #Thunderbird #Version 145
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:50:30 +0000
════════════════════════
⌗ Tags: #Technology #email client #EWS #Exchange #Microsoft 365 #mozilla #open_source #Outlook #Productivity #Thunderbird #Version 145
Daily CyberSecurity
Thunderbird 145: Native Microsoft Exchange Support Makes Outlook Migration Easy!
Thunderbird 145.0 now includes full, native support for Microsoft Exchange (EWS), eliminating plugins and making migration from Outlook/M365 accounts seamless!
⤷ Title: EU Launches DMA Probes: Is Gatekeeper Status Next for AWS & Azure Cloud?
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:46:43 +0000
════════════════════════
⌗ Tags: #Technology #Amazon AWS #Big Tech Regulation #Cloud Computing #Competition #Digital Markets Act #DMA #EU #gatekeeper #Microsoft Azure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:46:43 +0000
════════════════════════
⌗ Tags: #Technology #Amazon AWS #Big Tech Regulation #Cloud Computing #Competition #Digital Markets Act #DMA #EU #gatekeeper #Microsoft Azure
Daily CyberSecurity
EU Launches DMA Probes: Is Gatekeeper Status Next for AWS & Azure Cloud?
The EU is investigating if Amazon AWS and Microsoft Azure must be named DMA gatekeepers, facing strict new rules to ensure fair cloud competition in Europe.
⤷ Title: Google Extends FREE AI Pro Subscription for Students Until 2027
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:26:58 +0000
════════════════════════
⌗ Tags: #Technology #AI Tools #Deep Research #Education #free subscription #Gemini Pro #Google AI Pro #Google Drive #NotebookLM #student discount
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 08:26:58 +0000
════════════════════════
⌗ Tags: #Technology #AI Tools #Deep Research #Education #free subscription #Gemini Pro #Google AI Pro #Google Drive #NotebookLM #student discount
Daily CyberSecurity
Google Extends FREE AI Pro Subscription for Students Until 2027
U.S. university students can now keep their free Google AI Pro subscription, 2TB Drive, and access to Gemini 3 Pro/NotebookLM until May 2027!