⤷ Title: TryHackMe-TakeOver-WriteUp
════════════════════════
𐀪 Author: GUERD Nawal
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 23:26:26 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #cybersecurity #subdomain_takeover #writeup
════════════════════════
𐀪 Author: GUERD Nawal
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 23:26:26 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #cybersecurity #subdomain_takeover #writeup
Medium
TryHackMe-TakeOver-WriteUp
Difficulty: Easy
⤷ Title: REMINDER: Call for Speakers for “VulnCon 2026” Closes on December 22, 2025
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 23:24:59 GMT
════════════════════════
⌗ Tags: #vulnerability #information_technology #cybersecurity #vulnerability_management #information_security
════════════════════════
𐀪 Author: CVE Program Blog
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 23:24:59 GMT
════════════════════════
⌗ Tags: #vulnerability #information_technology #cybersecurity #vulnerability_management #information_security
Medium
REMINDER: Call for Speakers for “VulnCon 2026” Closes on December 22, 2025
The Call for Speakers (CFS) for CVE/FIRST VulnCon 2026 closes on December 22, 2025. VulnCon 2026 will be held on April 13–16, 2026, at the…
⤷ Title: CVE-2025–55182 Explained — Technical Analysis and Validation of the Attack Vector in React Server…
════════════════════════
𐀪 Author: Santiago Habib
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:40:33 GMT
════════════════════════
⌗ Tags: #vulnerability #react #exploit_development #nextjs #cybersecurity
════════════════════════
𐀪 Author: Santiago Habib
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:40:33 GMT
════════════════════════
⌗ Tags: #vulnerability #react #exploit_development #nextjs #cybersecurity
Medium
CVE-2025–55182 Explained — Technical Analysis and Validation of the Attack Vector in React Server…
CVE-2025–55182 and CVE-2025–66478
⤷ Title: How to Write an Executive Summary
════════════════════════
𐀪 Author: Cyberoptic Security
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:39:29 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #executive_reporting #reporting #penetration_testing
════════════════════════
𐀪 Author: Cyberoptic Security
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:39:29 GMT
════════════════════════
⌗ Tags: #pentesting #cybersecurity #executive_reporting #reporting #penetration_testing
Medium
How to Write an Executive Summary
The final outcome of most penetration tests is the report, and it is often the part dreaded most by the consultants carrying out the test…
⤷ Title: CVE-2025–55182 Explicado — Análisis Técnico y Validación del Vector de Ataque en React Server…
════════════════════════
𐀪 Author: Santiago Habib
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:32:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #nextjs #vulnerability #exploit_development #react
════════════════════════
𐀪 Author: Santiago Habib
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:32:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #nextjs #vulnerability #exploit_development #react
Medium
CVE-2025–55182 Explicado — Análisis Técnico y Validación del Vector de Ataque en React Server…
Autor: Santiago Habib
Fecha: Diciembre 2025
Fecha: Diciembre 2025
⤷ Title: Commands That Turn Your Own System Against You
════════════════════════
𐀪 Author: Liam
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:02:11 GMT
════════════════════════
⌗ Tags: #programming #cybersecurity #bash #technology #linux
════════════════════════
𐀪 Author: Liam
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:02:11 GMT
════════════════════════
⌗ Tags: #programming #cybersecurity #bash #technology #linux
Medium
Commands That Turn Your Own System Against You
The scariest cyber threats aren’t always hackers — sometimes they’re one careless keystroke away.
⤷ Title: Exploiting Logic Flaws & Zip Slips: A Walkthrough of “Desires” on Hack The Box
════════════════════════
𐀪 Author: Muhammad Younas
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:08:08 GMT
════════════════════════
⌗ Tags: #penetration_testing #hackthebox_writeup #hackthebox #desire #static_code_analysis
════════════════════════
𐀪 Author: Muhammad Younas
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:08:08 GMT
════════════════════════
⌗ Tags: #penetration_testing #hackthebox_writeup #hackthebox #desire #static_code_analysis
Medium
Exploiting Logic Flaws & Zip Slips: A Walkthrough of “Desires” on Hack The Box
Category: Web | Difficulty: Easy (But I think it should be a Medium Difficulty :) )
⤷ Title: Unlock x Benefits & Rewards — December 2025
════════════════════════
𐀪 Author: BEAST
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:15:11 GMT
════════════════════════
⌗ Tags: #bonus #blockchain #rewards #xs #crypto
════════════════════════
𐀪 Author: BEAST
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 22:15:11 GMT
════════════════════════
⌗ Tags: #bonus #blockchain #rewards #xs #crypto
Medium
x Airdrop Guide — Claim Tokens Now! 🚀 [December 2025]
Discover how to access and benefit from the latest x reward program.
⤷ Title: ShadyPanda Spyware Hacked 4.3 Million Users by Weaponizing Trusted Browser Extensions via Auto-Updates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:33:15 +0000
════════════════════════
⌗ Tags: #Vulnerability #Auto_Update #browser extension #Chrome Web Store #Clean Master #RCE Backdoor #ShadyPanda #spyware #WeTab
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:33:15 +0000
════════════════════════
⌗ Tags: #Vulnerability #Auto_Update #browser extension #Chrome Web Store #Clean Master #RCE Backdoor #ShadyPanda #spyware #WeTab
Daily CyberSecurity
ShadyPanda Spyware Hacked 4.3 Million Users by Weaponizing Trusted Browser Extensions via Auto-Updates
Koi Security exposed ShadyPanda, which infected 4.3M+ users by weaponizing trusted browser extensions (WeTab, Clean Master) through auto-updates. The malware performs RCE and exfiltrates data to China.
⤷ Title: Matanbuchus 3.0 Downloader Pivots to Ransomware, Using Protobufs and QuickAssist for Stealth Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:28:12 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #evasion #MaaS #Matanbuchus 3.0 #Protobufs #QuickAssist #ransomware #Zscaler
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:28:12 +0000
════════════════════════
⌗ Tags: #Malware #DLL Sideloading #evasion #MaaS #Matanbuchus 3.0 #Protobufs #QuickAssist #ransomware #Zscaler
Daily CyberSecurity
Matanbuchus 3.0 Downloader Pivots to Ransomware, Using Protobufs and QuickAssist for Stealth Access
Zscaler exposed Matanbuchus v3.0, a MaaS downloader pivoting to ransomware. The stealthy C++ malware uses Protobufs for C2, QuickAssist for access, and time-wasting loops to bypass sandboxes.
⤷ Title: Synology BeeStation Flaw Chain Leads to Root RCE Via Novel “Dirty File Write” SQL Injection, PoC Available
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:22:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CRLF Injection #Dirty File Write #privilege escalation #Pwn2Own #rce #sql injection #Synology BeeStation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:22:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CRLF Injection #Dirty File Write #privilege escalation #Pwn2Own #rce #sql injection #Synology BeeStation
Daily CyberSecurity
Synology BeeStation Flaw Chain Leads to Root RCE Via Novel "Dirty File Write" SQL Injection, PoC Available
A 3-flaw chain (CRLF, Auth Bypass, SQLi) achieves root RCE on Synology BeeStation. The exploit uses a "Dirty File Write" SQLi to inject a malicious crontab entry, bypassing the lack of a PHP interpreter.
⤷ Title: Water Saci Campaign Uses LLMs to Convert Malware to Python, Spreads Banking Trojan Via WhatsApp Worm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:19:58 +0000
════════════════════════
⌗ Tags: #Malware #AI_Assisted Malware #Banking Trojan #Brazil #LLM Conversion #Trend Micro #Water Saci #WhatsApp Worm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:19:58 +0000
════════════════════════
⌗ Tags: #Malware #AI_Assisted Malware #Banking Trojan #Brazil #LLM Conversion #Trend Micro #Water Saci #WhatsApp Worm
Daily CyberSecurity
Water Saci Campaign Uses LLMs to Convert Malware to Python, Spreads Banking Trojan Via WhatsApp Worm
Trend Micro exposed Water Saci, a campaign using LLMs to convert malware from PowerShell to Python, accelerating its spread via a WhatsApp worm. The multi-stage attack deploys a trojan capable of VNC mirroring and overlay attacks.
⤷ Title: High-Severity Vim for Windows Flaw (CVE-2025-66476) Risks Arbitrary Code Execution from Compromised Folders
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:15:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVE_2025_66476 #rce #text editor #Uncontrolled Search Path #vim #windows
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:15:31 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CVE_2025_66476 #rce #text editor #Uncontrolled Search Path #vim #windows
Daily CyberSecurity
High-Severity Vim for Windows Flaw (CVE-2025-66476) Risks Arbitrary Code Execution from Compromised Folders
A High-severity Vim for Windows flaw (CVE-2025-66476) allows arbitrary code execution. The editor executes malicious binaries in the current working directory instead of safe system paths when running commands like :grep.
⤷ Title: AWS Nova Forge: Open-Training Platform Enables Deep Customization of Nova 2 Models
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:12:20 +0000
════════════════════════
⌗ Tags: #Technology #Alexa #Amazon Bedrock #AWS Nova Forge #Customization #enterprise AI #Fine_Tuning #Generative AI #Nova 2 #Open_Training
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:12:20 +0000
════════════════════════
⌗ Tags: #Technology #Alexa #Amazon Bedrock #AWS Nova Forge #Customization #enterprise AI #Fine_Tuning #Generative AI #Nova 2 #Open_Training
Daily CyberSecurity
AWS Nova Forge: Open-Training Platform Enables Deep Customization of Nova 2 Models
AWS Nova Forge allows deep customization of Nova 2 models via open-training (pre-, mid-, post-training). This ensures reliable AI outputs aligned with enterprise operational constraints.
⤷ Title: Android 16 Update: AI Notification Summaries & Gemini-Powered Accessibility Suite
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:10:23 +0000
════════════════════════
⌗ Tags: #Android #accessibility #AI Notifications #Android 16 #Circle to Search #dark theme #Expressive Captions #Gemini #Pixel Update #TalkBack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:10:23 +0000
════════════════════════
⌗ Tags: #Android #accessibility #AI Notifications #Android 16 #Circle to Search #dark theme #Expressive Captions #Gemini #Pixel Update #TalkBack
Daily CyberSecurity
Android 16 Update: AI Notification Summaries & Gemini-Powered Accessibility Suite
Android 16's second update brings AI notification summaries and anti-scam tools. Accessibility gains Gemini-powered TalkBack and Expressive Captions for enhanced user experience.
⤷ Title: Raspberry Pi Price Hike: AI Boom Forces Price Increases on Pi 4 and Pi 5 Models
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:08:32 +0000
════════════════════════
⌗ Tags: #Technology #AI Demand #Compute Module #Eben Upton #LPDDR #Memory Costs #Price Increase #Raspberry Pi #Raspberry Pi 5
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:08:32 +0000
════════════════════════
⌗ Tags: #Technology #AI Demand #Compute Module #Eben Upton #LPDDR #Memory Costs #Price Increase #Raspberry Pi #Raspberry Pi 5
Daily CyberSecurity
Raspberry Pi Price Hike: AI Boom Forces Price Increases on Pi 4 and Pi 5 Models
Raspberry Pi raised prices on Pi 4 and Pi 5 models by up to $25, citing AI-driven memory demand. It simultaneously launched a new $45, 1GB Pi 5 entry model.
⤷ Title: AWS S3 Unleashed: Native Vector Storage & 50 TB Max Object Size for AI/Big Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:06:41 +0000
════════════════════════
⌗ Tags: #Technology #50 TB Object #Amazon S3 Vectors #AWS re:Invent #AWS S3 #big data #Generative AI #Iceberg Tables #RAG #Vector Database
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:06:41 +0000
════════════════════════
⌗ Tags: #Technology #50 TB Object #Amazon S3 Vectors #AWS re:Invent #AWS S3 #big data #Generative AI #Iceberg Tables #RAG #Vector Database
Daily CyberSecurity
AWS S3 Unleashed: Native Vector Storage & 50 TB Max Object Size for AI/Big Data
⤷ Title: AWS Frontier Agents: Autonomous AI ‘Team Members’ Take Over Dev, Security, and Ops
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:03:58 +0000
════════════════════════
⌗ Tags: #Technology #Agentic AI #Autonomous AI #AWS Frontier Agents #cybersecurity #DevOps #Kiro #re:Invent 2025 #Software Engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:03:58 +0000
════════════════════════
⌗ Tags: #Technology #Agentic AI #Autonomous AI #AWS Frontier Agents #cybersecurity #DevOps #Kiro #re:Invent 2025 #Software Engineering
Daily CyberSecurity
AWS Frontier Agents: Autonomous AI 'Team Members' Take Over Dev, Security, and Ops
AWS launched Frontier Agents, a new class of autonomous AI agents (Kiro, Security Agent, DevOps Agent) capable of long-running, independent software engineering tasks.
⤷ Title: AWS Unveils Nova 2 AI Model Family with Multimodal Omni & Agentic Nova Act
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:00:45 +0000
════════════════════════
⌗ Tags: #Technology #Agentic AI #AWS #Claude #Gemini #Generative AI #LLM #Multimodal Model #Nova 2 #Nova Act #Nova Forge #re:Invent 2025
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 00:00:45 +0000
════════════════════════
⌗ Tags: #Technology #Agentic AI #AWS #Claude #Gemini #Generative AI #LLM #Multimodal Model #Nova 2 #Nova Act #Nova Forge #re:Invent 2025
Daily CyberSecurity
AWS Unveils Nova 2 AI Model Family with Multimodal Omni & Agentic Nova Act
AWS launched the Nova 2 model family (Lite, Pro, Omni) and Nova Act, an agent platform achieving 90% reliability in web-browsing tasks, with Nova Forge for deep customization.
⤷ Title: DC3 vulnlabWalkthrough
════════════════════════
𐀪 Author: Miftahunnaufal Hidayat
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 01:31:30 GMT
════════════════════════
⌗ Tags: #hacking
════════════════════════
𐀪 Author: Miftahunnaufal Hidayat
════════════════════════
ⴵ Time: Thu, 04 Dec 2025 01:31:30 GMT
════════════════════════
⌗ Tags: #hacking
Medium
DC3 vulnlabWalkthrough
Now I want to share how I solved the vulnlab from vulnhub, namely dc3. Let’s go straight to the method.