10/02

Red Hat confirms security incident after hackers breach GitLab instance

https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-claim-github-breach/
Red Hat confirms security incident after hackers breach GitLab instance

Clop extortion emails claim theft of Oracle E-Business Suite data

https://www.bleepingcomputer.com/news/security/emails-claim-oracle-data-theft-in-new-clop-linked-extortion-campaign/
Clop extortion emails claim theft of Oracle E-Business Suite data

LOLBAS

http://LOLBAS-Project.github.io
LOLBAS

Indirect Memory Writing - Unprotect Project

https://unprotect.it/technique/indirect-memory-writing/
Indirect Memory Writing - Unprotect Project

Microsoft Outlook stops displaying inline SVG images used in attacks

https://www.bleepingcomputer.com/news/security/microsoft-outlook-stops-displaying-inline-svg-images-used-in-attacks/
Microsoft Outlook stops displaying inline SVG images used in attacks

GitHub - hkl1x/Bypass_AV: 免杀木马样本

https://github.com/hkl1x/Bypass_AV
GitHub - hkl1x/Bypass_AV: 免杀木马样本

Brewing Trouble: Homebrew Spoofed Sites on the Rise | The Sequence

https://the-sequence.com/brewing-trouble-homebrew-spoofed-sites-rise
Brewing Trouble: Homebrew Spoofed Sites on the Rise | The Sequence

Lunar Spider Expands their Web via FakeCaptcha – NVISO Labs

https://blog.nviso.eu/2025/10/01/lunar-spider-expands-their-web-via-fakecaptcha/
Lunar Spider Expands their Web via FakeCaptcha – NVISO Labs

Android spyware campaigns impersonate Signal and ToTok messengers

https://www.bleepingcomputer.com/news/security/android-spyware-campaigns-impersonate-signal-and-totok-messengers/
Android spyware campaigns impersonate Signal and ToTok messengers

sprawl.nyc

http://sprawl.nyc
sprawl.nyc

New spyware campaigns target privacy-conscious Android users in the UAE

https://www.welivesecurity.com/en/eset-research/new-spyware-campaigns-target-privacy-conscious-android-users-uae/
New spyware campaigns target privacy-conscious Android users in the UAE

Windows BitLocker -- Screwed without a Screwdriver — Neodyme

https://neodyme.io/en/blog/bitlocker_screwed_without_a_screwdriver
Windows BitLocker -- Screwed without a Screwdriver — Neodyme

New bug in classic Outlook can only be fixed via Microsoft support

https://www.bleepingcomputer.com/news/microsoft/new-bug-in-classic-outlook-can-only-be-fixed-via-microsoft-support/
New bug in classic Outlook can only be fixed via Microsoft support

HackerOne paid $81 million in bug bounties over the past year

https://www.bleepingcomputer.com/news/security/hackerone-paid-81-million-in-bug-bounties-over-the-past-year/
HackerOne paid $81 million in bug bounties over the past year

DrayTek warns of remote code execution bug in Vigor routers

https://www.bleepingcomputer.com/news/security/draytek-warns-of-remote-code-execution-bug-in-vigor-routers/
DrayTek warns of remote code execution bug in Vigor routers

Rhadamanthys 0.9.x - walk through the updates - Check Point Research

https://research.checkpoint.com/2025/rhadamanthys-0-9-x-walk-through-the-updates/
Rhadamanthys 0.9.x - walk through the updates - Check Point Research