06/13

Make Self-XSS Great Again - Slonser Notes

https://blog.slonser.info/posts/make-self-xss-great-again/
Make Self-XSS Great Again - Slonser Notes

Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware

https://thehackernews.com/2025/06/apple-zero-click-flaw-in-messages.html
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware

Google links massive cloud outage to API management issue

https://www.bleepingcomputer.com/news/google/google-links-massive-cloud-outage-to-api-management-issue/
Google links massive cloud outage to API management issue

Inside a Dark Adtech Empire Fed by Fake CAPTCHAs – Krebs on Security

https://krebsonsecurity.com/2025/06/inside-a-dark-adtech-empire-fed-by-fake-captchas/
Inside a Dark Adtech Empire Fed by Fake CAPTCHAs – Krebs on Security

Discord flaw lets hackers reuse expired invites in malware campaign

https://www.bleepingcomputer.com/news/security/discord-flaw-lets-hackers-reuse-expired-invites-in-malware-campaign/
Discord flaw lets hackers reuse expired invites in malware campaign

Cloudflare: Outage not caused by security incident, data is safe

https://www.bleepingcomputer.com/news/security/cloudflare-outage-not-caused-by-security-incident-data-is-safe/
Cloudflare: Outage not caused by security incident, data is safe

270K websites injected with ‘JSF-ck’ obfuscated code | SC Media

https://www.scworld.com/news/270k-websites-injected-with-jsf-ck-obfuscated-code
270K websites injected with ‘JSF-ck’ obfuscated code | SC Media

Graphite Caught: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab

https://citizenlab.ca/2025/06/first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted/
Graphite Caught: First Forensic Confirmation of Paragon’s iOS Mercenary Spyware Finds Journalists Targeted - The Citizen Lab

GitHub - DevBuiHieu/CVE-2025-33053-Proof-Of-Concept: CVE-2025-33053 Proof Of Concept (PoC)

https://github.com/DevBuiHieu/CVE-2025-33053-Proof-Of-Concept
GitHub - DevBuiHieu/CVE-2025-33053-Proof-Of-Concept: CVE-2025-33053 Proof Of Concept (PoC)

Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion

https://thehackernews.com/2025/06/ransomware-gangs-exploit-unpatched.html
Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion

Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices

https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5060533-update-triggers-boot-errors-on-surface-hub-v1-devices/
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices

Microsoft confirms auth issues affecting Microsoft 365 users

https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-auth-issues-affecting-microsoft-365-users/
Microsoft confirms auth issues affecting Microsoft 365 users

Victoria’s Secret restores critical systems after cyberattack

https://www.bleepingcomputer.com/news/security/victorias-secret-restores-critical-systems-after-cyberattack/
Victoria’s Secret restores critical systems after cyberattack

FortiOS SSL-VPN Vulnerability Let Attackers Access full SSL-VPN settings

https://cybersecuritynews.com/fortios-ssl-vpn-vulnerability/
FortiOS SSL-VPN Vulnerability Let Attackers Access full SSL-VPN settings

New 'SmartAttack' Steals Air-Gapped Data Using Smartwatches - SecurityWeek

https://www.securityweek.com/new-smartattack-steals-air-gapped-data-using-smartwatches/
New 'SmartAttack' Steals Air-Gapped Data Using Smartwatches - SecurityWeek

Predator Spyware Resurgence: Insikt Group Exposes New Global Infrastructure

https://www.recordedfuture.com/research/predator-still-active-new-links-identified
Predator Spyware Resurgence: Insikt Group Exposes New Global Infrastructure

Release v1.1.0 · VirusTotal/yara-x · GitHub

https://github.com/VirusTotal/yara-x/releases/tag/v1.1.0
Release v1.1.0 · VirusTotal/yara-x · GitHub