■■■■□ Notepad++ Vulnerability Let Attackers Hijack Network Traffic to Install Malware via Updates.
https://cybersecuritynews.com/notepad-vulnerability-exploited/
https://cybersecuritynews.com/notepad-vulnerability-exploited/
Cyber Security News
Notepad++ Vulnerability Let Attackers Hijack Network Traffic to Install Malware via Updates
The popular text editor Notepad++ has addressed a severe security weakness in its update mechanism that could allow attackers to hijack network traffic and push malicious executables to users under the guise of legitimate updates.
■■■□□ United States 🇺🇸 Space Force receives first satellite jamming system.
https://defence-blog.com/u-s-space-force-receives-first-satellite-jamming-system/
https://defence-blog.com/u-s-space-force-receives-first-satellite-jamming-system/
Defence Blog – Military and Defense News
U.S. Space Force receives first satellite jamming system
L3Harris Technologies has delivered the first production Meadowlands Counter Communications System to the U.S. Space Force Combat Forces Command’s Mission Delta 3 – Space Electromagnetic Warfare unit. According to a statement from the company, the delivery…
🤯1
■■■■■ React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation.
https://thehackernews.com/2025/12/react2shell-exploitation-escalates-into.html
https://www.cisa.gov/news-events/alerts/2025/12/05/cisa-adds-one-known-exploited-vulnerability-catalog
https://thehackernews.com/2025/12/react2shell-exploitation-escalates-into.html
https://www.cisa.gov/news-events/alerts/2025/12/05/cisa-adds-one-known-exploited-vulnerability-catalog
■■■■□ ⚠️ Notepad++ fixes a bug that was actively abused.
Notepad++ released version 8.8.9 to patch a critical updater flaw. Attackers hijacked update traffic and tricked users into installing malware instead of real updates.
https://thehackernews.com/2025/12/threatsday-bulletin-spyware-alerts.html
Notepad++ released version 8.8.9 to patch a critical updater flaw. Attackers hijacked update traffic and tricked users into installing malware instead of real updates.
https://thehackernews.com/2025/12/threatsday-bulletin-spyware-alerts.html
❤1
■■□□□ Open AI caught up in propaganda. Key employee quits!
OpenAI Researcher Quits, Saying Company Is Hiding the Truth. It's not letting potentially damning research get out there.
https://futurism.com/artificial-intelligence/openai-researcher-quits-hiding-truth
OpenAI Researcher Quits, Saying Company Is Hiding the Truth. It's not letting potentially damning research get out there.
https://futurism.com/artificial-intelligence/openai-researcher-quits-hiding-truth
Futurism
OpenAI Researcher Quits, Saying Company Is Hiding the Truth
OpenAI is making it hard for its researchers to publish research that tells the truth of AI's potentially negative economic impact.
👍1
■■■■□ Shannon – AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits.
https://github.com/KeygraphHQ/shannon
https://cybersecuritynews.com/shannon-ai-pentesting-tool/
https://github.com/KeygraphHQ/shannon
https://cybersecuritynews.com/shannon-ai-pentesting-tool/
Cyber Security News
Shannon – AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits
Shannon is a fully autonomous AI pentesting tool for web applications that identifies attack vectors via code analysis and validates them with live browser exploits.
👍1
■■■■□ A critical security issue involving the Windows Remote Access Connection Manager (RasMan) that allows local attackers to execute arbitrary code with System privileges.
While investigating CVE-2025-59230, the vulnerability that Microsoft addressed in the October 2025 security updates. 0patch security analysts discovered a complex exploit chain that relies on a secondary, previously unknown zero-day flaw to function effectively.
https://cybersecuritynews.com/windows-remote-access-connection-manager-vulnerability/
While investigating CVE-2025-59230, the vulnerability that Microsoft addressed in the October 2025 security updates. 0patch security analysts discovered a complex exploit chain that relies on a secondary, previously unknown zero-day flaw to function effectively.
https://cybersecuritynews.com/windows-remote-access-connection-manager-vulnerability/
Cyber Security News
Windows Remote Access Connection Manager Vulnerability Enables Arbitrary Code Execution
A critical security issue involving the Windows Remote Access Connection Manager (RasMan) that allows local attackers to execute arbitrary code with System privileges.
■■■■□ Data-Leak of Military technology. A fully intact GBU-39 from United States 🇺🇸 was dropped on Lebanon 🇱🇧 weeks ago to kill top Hizbollah Shit'te commander. 8 strikes, 7 explode, 1 was dud.
The dud was recovered. Now US is pressuring Lebanese government to return the dud. The technology is being now reverse engineered by resistance fighters. Likely shared to Iran 🇮🇷 / Russia 🇷🇺
https://www.indiatoday.in/world/story/us-gbu-39b-unexploded-bomb-lebanon-return-glbs-2827246-2025-11-28
https://www.jpost.com/middle-east/article-876530
https://www.instagram.com/reel/DRfNQpkDywD
The dud was recovered. Now US is pressuring Lebanese government to return the dud. The technology is being now reverse engineered by resistance fighters. Likely shared to Iran 🇮🇷 / Russia 🇷🇺
https://www.indiatoday.in/world/story/us-gbu-39b-unexploded-bomb-lebanon-return-glbs-2827246-2025-11-28
https://www.jpost.com/middle-east/article-876530
https://www.instagram.com/reel/DRfNQpkDywD
India Today
US wants Lebanon to hand back unexploded GBU-39B bomb from Beirut strike
The claim has drawn significant attention amid fears that sensitive US technology could be exposed during Israel’s operations across Lebanon. Lebanese officials have not publicly confirmed whether the device is in their custody or how they intend to handle…
■■■□□ Signal Intelligence, Reconnaissance esp wrt. aerial targets and other technologies of electronic warfare were shared by Israeli Elbit systems with Ministry of Defence of UAE 🇦🇪 with 2.3 Billion USD.
This is highest amount of money in any deal Elbit has ever seen.
This is highest amount of money in any deal Elbit has ever seen.
❤1
Forwarded from cKure Red
https://www.iranintl.com/en/202512164597
Please open Telegram to view this post
VIEW IN TELEGRAM
Iranintl
Iran-linked hacker group offers $30,000 bounty for Israel's military info
An Iran-linked hacker group said it was offering a $30,000 reward for information related to Israel’s military sector after releasing material it said identified people involved in designing Israeli missile defense systems.
👏3🔥1🤣1
■■■■□ North Korean infiltrator caught working in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true location.
https://www.tomshardware.com/tech-industry/cyber-security/north-korean-infiltrator-caught-working-in-amazon-it-department-thanks-to-lag-110ms-keystroke-input-raises-red-flags-over-true-location
A barely perceptible keystroke delay was the smoking gun that led to the uncovering of a malign imposter.https://www.tomshardware.com/tech-industry/cyber-security/north-korean-infiltrator-caught-working-in-amazon-it-department-thanks-to-lag-110ms-keystroke-input-raises-red-flags-over-true-location
Tom's Hardware
North Korean infiltrator caught working in Amazon IT department thanks to lag — 110ms keystroke input raises red flags over true…
A barely perceptible keystroke delay was the smoking gun that led to the uncovering of a malign imposter.
🔥2🌚1
■■■■□ A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.
https://github.com/Semperis/EntraGoat
https://github.com/Semperis/EntraGoat
GitHub
GitHub - Semperis/EntraGoat: A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on…
A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges. - Semperis/EntraGoat
■■■■□ ❌ Disinformation: A recently reported contract between Israel and Clock Tower Group, valued at $6 million, is aimed at shaping online narratives. Reports by Responsible Statecraft suggest this involves content production for disinformation and misinformation campaigns, potentially influencing platforms like ChatGPT. The agreement could be seen as a form of mass manipulation.
Please open Telegram to view this post
VIEW IN TELEGRAM
🤔2😡1
■■■□□ D-Link router DIR-553 * which have carrier / ISP owned custom firmware can be Jailbroken and remote commands can be executed in a specific configuration of FTP.
🔥3
■■■□□ NFC threats continued to grow in scale and sophistication.
RatOn Malware on the NFC fraud scene, brought a rare fusion of RAT capabilities and NFC relay attacks.
https://github.com/blackorbird/APT_REPORT/blob/master/summary/2025/eset-threat-report-h22025.pdf
RatOn Malware on the NFC fraud scene, brought a rare fusion of RAT capabilities and NFC relay attacks.
https://github.com/blackorbird/APT_REPORT/blob/master/summary/2025/eset-threat-report-h22025.pdf
GitHub
APT_REPORT/summary/2025/eset-threat-report-h22025.pdf at master · blackorbird/APT_REPORT
Interesting APT Report Collection And Some Special IOCs - blackorbird/APT_REPORT
🥰2🤯1🌭1
Forwarded from cKure Red
This media is not supported in your browser
VIEW IN TELEGRAM
OSINT via Google 🔍
Please open Telegram to view this post
VIEW IN TELEGRAM
🥰1😱1