06/17

New Veeam RCE flaw lets domain users hack backup servers

https://www.bleepingcomputer.com/news/security/new-veeam-rce-flaw-lets-domain-users-hack-backup-servers/
New Veeam RCE flaw lets domain users hack backup servers

Zyxel NWA50AX Pro - Discovery of an Nday Variant | Frycos Security Diary

https://frycos.github.io/vulns4free/2025/06/17/zyxel-nday-variant.html
Zyxel NWA50AX Pro - Discovery of an Nday Variant | Frycos Security Diary

OtterCookie: Analysis of New Lazarus Group Malware

https://any.run/cybersecurity-blog/ottercookie-malware-analysis/
OtterCookie: Analysis of New Lazarus Group Malware

Fast and Curious: Red Teaming, Race Cars, and Hunt.io with Justin Elze

https://hunt.io/blog/trustedsec-cto-interview-justin-elze
Fast and Curious: Red Teaming, Race Cars, and Hunt.io with Justin Elze

Sign Up | LinkedIn

https://www.linkedin.com/posts/activity-7340831666447294464-tGOg?rcm=ACoAACejwu4BPPb58lcfSK7rsk4nC20JS4qAPvM
Sign Up | LinkedIn

【V8】pwncollege V8 Exploitation WP上 | Loora1N's Blog | 鹭雨

https://loora1n.github.io/2024/11/27/%E3%80%90v8%E3%80%91pwncollege%20V8%20Exploitation%20WP/
【V8】pwncollege V8 Exploitation WP上 | Loora1N's Blog | 鹭雨

Sitecore CMS exploit chain starts with hardcoded 'b' password

https://www.bleepingcomputer.com/news/security/sitecore-cms-exploit-chain-starts-with-hardcoded-b-password/
Sitecore CMS exploit chain starts with hardcoded 'b' password

Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor

https://thehackernews.com/2025/06/google-chrome-zero-day-cve-2025-2783.html
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor

TP-Link Router Flaw CVE-2023-33538 Under Active Exploit, CISA Issues Immediate Alert

https://thehackernews.com/2025/06/tp-link-router-flaw-cve-2023-33538.html
TP-Link Router Flaw CVE-2023-33538 Under Active Exploit, CISA Issues Immediate Alert

Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms

https://thehackernews.com/2025/06/google-warns-of-scattered-spider.html
Google Warns of Scattered Spider Attacks Targeting IT Support Teams at U.S. Insurance Firms

Scania confirms insurance claim data breach in extortion attempt

https://www.bleepingcomputer.com/news/security/scania-confirms-insurance-claim-data-breach-in-extortion-attempt/
Scania confirms insurance claim data breach in extortion attempt

Hacker steals 1 million Cock.li user records in webmail data breach

https://www.bleepingcomputer.com/news/security/hacker-steals-1-million-cockli-user-records-in-webmail-data-breach/
Hacker steals 1 million Cock.li user records in webmail data breach

How to Kernel Debug With Windows Sandbox | Max Renke

https://blog.maxrenke.com/How-to-Kernel-Debug-With-Windows-Sandbox/
How to Kernel Debug With Windows Sandbox | Max Renke

Is b For Backdoor? Pre-Auth RCE Chain In Sitecore Experience Platform

https://labs.watchtowr.com/is-b-for-backdoor-pre-auth-rce-chain-in-sitecore-experience-platform/
Is b For Backdoor? Pre-Auth RCE Chain In Sitecore Experience Platform

New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS Attacks

https://thehackernews.com/2025/06/new-flodrix-botnet-variant-exploits.html
New Flodrix Botnet Variant Exploits Langflow AI Server RCE Bug to Launch DDoS Attacks

【V8】pwncollege V8 Exploitation WP中 | Loora1N's Blog | 鹭雨

https://loora1n.github.io/2024/12/02/%E3%80%90v8%E3%80%91pwncollege%20V8%20Exploitation%20WP-2/
【V8】pwncollege V8 Exploitation WP中 | Loora1N's Blog | 鹭雨

Positive Hack Talks Jakarta :: pretalx

http://cfp.phdays.com/phtalks-jakarta-2025/cfp
Positive Hack Talks Jakarta :: pretalx

Path Traversal Vulnerability Discovered in ZendTo | Horizon3.ai

https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/
Path Traversal Vulnerability Discovered in ZendTo | Horizon3.ai

ASUS Armoury Crate bug lets attackers get Windows admin privileges

https://www.bleepingcomputer.com/news/security/asus-armoury-crate-bug-lets-attackers-get-windows-admin-privileges/
ASUS Armoury Crate bug lets attackers get Windows admin privileges

Smart air fryers ordered to stop invading our digital privacy | Malwarebytes

https://www.malwarebytes.com/blog/news/2025/06/smart-air-fryers-ordered-to-stop-invading-our-digital-privacy
Smart air fryers ordered to stop invading our digital privacy | Malwarebytes

Silver Fox APT Targets Taiwan with Complex Gh0stCringe and HoldingHands RAT Malware

https://thehackernews.com/2025/06/silver-fox-apt-targets-taiwan-with.html
Silver Fox APT Targets Taiwan with Complex Gh0stCringe and HoldingHands RAT Malware

UK fines 23andMe for ‘profoundly damaging’ breach exposing genetics data

https://www.bleepingcomputer.com/news/security/uk-fines-23andme-for-profoundly-damaging-breach-exposing-genetics-data/
UK fines 23andMe for ‘profoundly damaging’ breach exposing genetics data