Update on Attacks by Threat Group APT-C-60 - JPCERT/CC Eyes | JPCERT Coordination Center official Blog
https://blogs.jpcert.or.jp/en/2025/11/APT-C-60_update.html
Exploiting CVE-2025-21479 on a Samsung S23
https://xploitbengineer.github.io/CVE-2025-21479
[하루한줄] CVE-2025-23271: NVIDIA nvdisasm의 heap overflow 취약점 - hackyboiz
https://hackyboiz.github.io/2025/11/05/ogu123/cve-2025-23271/
Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data
https://thehackernews.com/2025/11/researchers-find-chatgpt.html
Hackers Exploit OneDrive.exe Through DLL Sideloading to Execute Arbitrary Code
https://cybersecuritynews.com/onedrive-exe-dll-sideloading-with-malicious-dll-files/
Ryan Goldberg | SANS Institute
https://web.archive.org/web/20250515213435/https://www.sans.org/profiles/ryan-goldberg/
Signal Desktop Path Traversal vulnerability in Attachment Saving | by h4x0r_dz | Nov, 2025 | Medium
https://medium.com/@h4x0r_dz/signal-desktop-path-traversal-vulnerability-in-attachment-saving-e9de7806767e
CISA warns of critical CentOS Web Panel bug exploited in attacks
https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-centos-web-panel-bug-exploited-in-attacks/
GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog
https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-usage-of-ai-tools
How we built OWL, the new architecture behind our ChatGPT-based browser, Atlas | OpenAI
https://openai.com/index/building-chatgpt-atlas/
Hunting for EDR-Freeze
https://blog.axelarator.net/hunting-for-edr-freeze/
Microsoft removing Defender Application Guard from Office
https://www.bleepingcomputer.com/news/microsoft/microsoft-removing-defender-application-guard-from-office/
KITCTFCTF 2022 V8 Heap Sandbox Escape :: Home | ju256
https://ju256.rip/posts/kitctfctf22-date/
400,000 WordPress Sites Affected by Account Takeover Vulnerability in Post SMTP WordPress Plugin
https://www.wordfence.com/blog/2025/11/400000-wordpress-sites-affected-by-account-takeover-vulnerability-in-post-smtp-wordpress-plugin/
Depicting an iOS Vulnerability – DFSEC Research
https://blog.dfsec.com/ios/2025/10/14/Depicting-an-iOS-Vulnerability/
Google warns of new AI-powered malware families deployed in the wild
https://www.bleepingcomputer.com/news/security/google-warns-of-new-ai-powered-malware-families-deployed-in-the-wild/
Gootloader malware is back with new tricks after 7-month break
https://www.bleepingcomputer.com/news/security/gootloader-malware-is-back-with-new-tricks-after-7-month-break/
UK carriers to block spoofed phone numbers in fraud crackdown
https://www.bleepingcomputer.com/news/security/uk-carriers-to-block-spoofed-phone-numbers-in-fraud-crackdown/
Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly
https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html
U.S. Sanctions 10 North Korean Entities for Laundering $12.7M in Crypto and IT Fraud
https://thehackernews.com/2025/11/us-sanctions-10-north-korean-entities.html
Police busts credit card fraud rings with 4.3 million victims
https://www.bleepingcomputer.com/news/security/europol-credit-card-fraud-rings-stole-eur-300-million-from-43-million-cardholders/
University of Pennsylvania confirms data stolen in cyberattack
https://www.bleepingcomputer.com/news/security/university-of-pennsylvania-confirms-data-stolen-in-cyberattack/
Hyundai AutoEver America data breach exposes SSNs, drivers licenses
https://www.bleepingcomputer.com/news/security/hyundai-autoever-america-data-breach-exposes-ssns-drivers-licenses/
Mysterious 'SmudgedSerpent' Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions
https://thehackernews.com/2025/11/mysterious-smudgedserpent-hackers.html
Let’s Create Some Polymorphic PIC Shellcode! - G3tSyst3m’s Infosec Blog
https://g3tsyst3m.com/shellcode/pic/Let's-Create-Some-Polymorphic-PIC-Shellcode!/
Microsoft: October Windows updates trigger BitLocker recovery
https://www.bleepingcomputer.com/news/microsoft/microsoft-october-windows-updates-trigger-bitlocker-recovery/