■□□□□ IoT: Dashboards for Home Assistant.
https://github.com/Madelena/hass-config-public/?tab=readme-ov-file
https://github.com/Madelena/hass-config-public/?tab=readme-ov-file
GitHub
GitHub - Madelena/hass-config-public: My Dashboards for Home Assistant - Advanced data visualizations, responsive design, a neat…
My Dashboards for Home Assistant - Advanced data visualizations, responsive design, a neat maximalist Metro Live Tile layout, and an ultraminimal tablet layout! - Madelena/hass-config-public
This media is not supported in your browser
VIEW IN TELEGRAM
■■■□□ Israeli disinformation campaign / insights.
😡2🔥1🥰1👏1
■■■■□ Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs.
New research from CrowdStrike has revealed that DeepSeek's artificial intelligence (AI) reasoning model DeepSeek-R1 produces more security vulnerabilities in response to prompts that contain topics deemed politically sensitive by China.
https://thehackernews.com/2025/11/chinese-ai-model-deepseek-r1-generates.html
New research from CrowdStrike has revealed that DeepSeek's artificial intelligence (AI) reasoning model DeepSeek-R1 produces more security vulnerabilities in response to prompts that contain topics deemed politically sensitive by China.
https://thehackernews.com/2025/11/chinese-ai-model-deepseek-r1-generates.html
❤1
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3🔥2✍1👍1🥰1👏1👀1
■■■■□ New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions.
https://thehackernews.com/2025/11/new-fluent-bit-flaws-expose-cloud-to.html
https://thehackernews.com/2025/11/new-fluent-bit-flaws-expose-cloud-to.html
GitHub
GitHub - fluent/fluent-bit: Fast and Lightweight Logs, Metrics and Traces processor for Linux, BSD, OSX and Windows
Fast and Lightweight Logs, Metrics and Traces processor for Linux, BSD, OSX and Windows - fluent/fluent-bit
■□□□□ UAE: Public falls for ‘Free WiFi’ QR trap in Sharjah cybersecurity experiment.
https://gulfnews.com/uae/public-falls-for-free-wifi-qr-trap-in-sharjah-cybersecurity-experiment-1.500359662
The QR redirected to:
https://scanned.page/p/xD86lz
https://gulfnews.com/uae/public-falls-for-free-wifi-qr-trap-in-sharjah-cybersecurity-experiment-1.500359662
The QR redirected to:
https://scanned.page/p/xD86lz
Gulf News: Latest UAE news, Dubai news, Business, travel news, Dubai Gold rate, prayer time, cinema
Public falls for ‘Free WiFi’ QR trap in Sharjah cybersecurity experiment
Sharjah Police experiment shows public easily misled by fake QR codes
■■■■□ Cryptology firm cancels elections after losing encryption key.
https://www.bbc.co.uk/news/articles/c62vl05rz0ko
https://www.bbc.co.uk/news/articles/c62vl05rz0ko
BBC News
Cryptology firm cancels elections after losing encryption key
The International Association for Cryptologic Research - created to study secure communication - said it was an "honest human mistake."
🤣3👏1🙏1
■■■□□ What happens when you give Burp AI the bare minimum details and just let it hack by itself? Let's find out with 0xTib3rius.
https://youtu.be/1-NkCSW-IUU
https://youtu.be/1-NkCSW-IUU
YouTube
Can Burp AI Hack These Web Challenges?
How does Burp AI fare against web challenges from Hacking Hub and Portswigger Web Academy? I tried giving Burp's new agentic mode the bare minimum amount of information to see just how far it could go on its own.
Disclaimer: This was intended as a fun experiment…
Disclaimer: This was intended as a fun experiment…
❤1
■■■■■ Tor switches to new Counter Galois Onion relay encryption algorithm.
https://www.bleepingcomputer.com/news/security/tor-switches-to-new-counter-galois-onion-relay-encryption-algorithm/
https://www.bleepingcomputer.com/news/security/tor-switches-to-new-counter-galois-onion-relay-encryption-algorithm/
BleepingComputer
Tor switches to new Counter Galois Onion relay encryption algorithm
Tor has announced improved encryption and security for the circuit traffic by replacing the old tor1 relay encryption algorithm with a new design called Counter Galois Onion (CGO).
■■■■■ Botnet takes advantage of AWS outage to smack 28 countries.
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
https://www.theregister.com/2025/11/26/miraibased_botnet_shadowv2/
The Register
Botnet takes advantage of AWS outage to smack 28 countries
: Even worse, it might have been a 'test run' for future attacks
■■■■□ SectorA01 (Lazarus) employed a highly sophisticated, multi-stage attack chain
https://medium.com/@nshcthreatrecon/a-tsunami-sweeping-the-cyber-battlefield-analysis-of-sectora01s-hacking-activities-e4d006baae2f
https://x.com/blackorbird/status/1994001509944840678
beginning with social engineering via a fake official Deriv trading platform installer (NSIS-based).
The infection progresses through a polyglot payload sequence (NSIS → Electron/JavaScript → Python → .NET), using dynamic code execution via eval() on remotely fetched JavaScript, Pastebin as a dead-drop mechanism with 1,000 pre-generated XOR-encrypted URLs, and Living-off-the-Land techniques by downloading and installing the legitimate official Python interpreter when absent.
Once inside, the malware conducts broad data theft including browser credentials and credit-card information, keylogging with clipboard monitoring and exfiltration, and keyword-based recursive searches for sensitive files (wallet, mnemonic, .env, etc.).
It establishes strong remote access through an AnyDesk backdoor using a pre-configured fixed password via service.conf overwrite, while achieving multi-layered persistence through the startup folder, scheduled tasks, and AnyDesk auto-start.
Defense evasion is comprehensive: it disables Windows Defender and Firewall while adding exclusions, masquerades as the legitimate system process Runtime Broker.exe, tampers PE timestamps to future dates (2070 and 2093), communicates in the final stage exclusively over Tor via a .onion C2 domain, and incorporates automatic client updates with trace self-deletion to hinder detection and analysis.
https://medium.com/@nshcthreatrecon/a-tsunami-sweeping-the-cyber-battlefield-analysis-of-sectora01s-hacking-activities-e4d006baae2f
https://x.com/blackorbird/status/1994001509944840678
■■□□□ The Central Bank of India (RBI) 🇮🇳 has made a good decision from cyber security perspective.
They have forced all bank websites to be subdomains of bank.in
This will effectively cause most phishing campaigns to go astray.
🚫
They have forced all bank websites to be subdomains of bank.in
This will effectively cause most phishing campaigns to go astray.
Please open Telegram to view this post
VIEW IN TELEGRAM
■□□□ 💥 Cyber-War on Israel: Transport display outages; new details on cyber intrusion into "Urban Digital" company.
📱
https://t.me/CyberSecurityIL/8107
🎤Following a widespread disruption in transport information displays in the occupied territories, Hebrew sources confirmed that the incident originated from a cyber intrusion into the infrastructure of the "Urban Digital" company. This attack disabled parts of the smart displays in cities such as Ashkelon and Modiin for about an hour.
🎥The management of the company owning "Urban Digital" announced that to contain the incident, all servers were completely shut down and more than 100 experts were active until morning to control the situation.
🎤Initial assessment indicates that the attackers are from the same groups that have targeted several other organizations of this regime in recent months. Technical investigation is ongoing.
HackerNewsCyberhttps://t.me/CyberSecurityIL/8107
Please open Telegram to view this post
VIEW IN TELEGRAM
■■■□□ Alleged Disclosure of the identity of a 16-year-old teenager; the technical brain of the SLSH ransomware group from Amman, Jordan 🇯🇴
https://t.me/HackerNewscyber/2666
https://t.me/HackerNewscyber/2666
Telegram
هکرنیوز|Hacker News
🚨🚨افشای هویت نوجوان ۱۶ساله؛ مغز فنی گروه باجافزاری SLSH شناسایی شد
🎤در پی هفتهها بررسی منابع اطلاعاتی، هویت واقعی «Rey» یکی از سه مدیر اصلی گروه سایبری Scattered LAPSUS$ Hunters شناسایی و تأیید شد. گروهی که طی سال ۲۰۲۵ با سرقت داده و اخاذی از شرکتهای…
🎤در پی هفتهها بررسی منابع اطلاعاتی، هویت واقعی «Rey» یکی از سه مدیر اصلی گروه سایبری Scattered LAPSUS$ Hunters شناسایی و تأیید شد. گروهی که طی سال ۲۰۲۵ با سرقت داده و اخاذی از شرکتهای…
■□□□□ CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
https://access.redhat.com/errata/RHSA-2025:18231
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
https://access.redhat.com/errata/RHSA-2025:18231